Authentication Module Vulnerability in Apache HTTP Server by OpenIDC
CVE-2025-31492

8.2HIGH

Key Information:

Vendor

Openidc

Vendor
CVE Published:
6 April 2025

What is CVE-2025-31492?

The mod_auth_openidc component for the Apache HTTP server prior to version 2.4.16.11 contains a bug that may allow unauthenticated users to gain access to protected resources. This situation arises when specific conditions are met, including the use of a POST method for OIDCProviderAuthRequest and the absence of protective application-level gateways. In such cases, the software does not properly restrict access, leading to the accidental exposure of sensitive content, including HTTP statuses, headers, and intended responses. This issue affects the confidentiality of the resources and has been remedied in subsequent versions.

Affected Version(s)

mod_auth_openidc < 2.4.16.11

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.