VDB
BDU%3A2025-10948
BDU%3A2025-10948
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость модуля аутентификации и авторизации для Apache 2.x HTTP server Mod_auth_openidc, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Novell Inc., АО «СберТех», ZmartZone IAM | Red Hat Enterprise Linux, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, SUSE Liberty Linux, OpenSUSE Leap, SUSE Linux Enterprise Module for Server Applications, SUSE Linux Enterprise Server LTSS Extended Security, Platform V SberLinux OS Server (запись в едином реестре российских программ №18785), Mod_auth_openidc |
Timeline
- Sep 11, 2025 CVE Published
- Sep 30, 2025 CVE Updated
References
- https://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-x7cf-8wgv-5j86 advisory
- https://access.redhat.com/security/cve/cve-2025-3891 advisory
- https://security-tracker.debian.org/tracker/CVE-2025-3891 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html url
- https://www.suse.com/security/cve/CVE-2025-3891.html url