CVE-2021-32792 PUBLISHED

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.

EPSS 0.17% · 38.1th percentile

Risk Scores

EPSS Score
0.17%
38.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibapache2-mod-auth-openidc0, 2.4.0.4-1, 2.4.1-1
Ubuntu:18.04:LTSlibapache2-mod-auth-openidc2.3.3-1build1, 0, 2.1.6-1

Timeline

References

Open in Interactive Console →