PT-2017-4171 · Apache+5 · Mod Auth Openidc+5

Published

2017-01-30

·

Updated

2025-12-29

·

CVE-2021-32786

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mod auth openidc versions prior to 2.4.9
Description The issue is related to the oidc validate redirect url() function in mod auth openidc, which does not parse URLs the same way as most browsers do. This leads to an Open Redirect vulnerability in the logout functionality, allowing a remote attacker to access and compromise confidential data. The vulnerability can be mitigated by configuring mod auth openidc to only allow redirection whose destination matches a given regular expression.
Recommendations For versions prior to 2.4.9, update to version 2.4.9 or later, where the bug has been fixed by replacing any backslash of the URL to redirect with slashes. As a temporary workaround, consider configuring mod auth openidc to only allow redirection whose destination matches a given regular expression.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1823
AZL-6480
BDU:2022-01677
CESA-2022_1823
CVE-2021-32786
DLA-3409-1
GHSA-XM4C-5WM5-JQV7
MGASA-2021-0452
OPENSUSE-SU-2021:1277-1
OPENSUSE-SU-2021:3020-1
OPENSUSE-SU-2021_1277-1
OPENSUSE-SU-2021_3020-1
OPENSUSE-SU-2024:10624-1
RHSA-2022:1823
RHSA-2022_1823
RLSA-2022:1823
SUSE-SU-2021:3020-1
SUSE-SU-2021:3352-1
SUSE-SU-2025:4532-1

Affected Products

Almalinux
Centos
Red Hat
Rocky Linux
Suse
Mod Auth Openidc