PT-2020-10464 · Apache+5 · Mod Auth Openidc+5

Ret2Libc

·

Published

2020-02-20

·

Updated

2025-12-29

·

CVE-2019-20479

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mod auth openidc versions prior to 2.4.1
Description A flaw exists in the handling of URLs with a slash and backslash at the beginning, leading to an open redirect issue.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALSA-2020:3032
CESA-2020_3032
CESA-2020_3970
CVE-2019-20479
DLA-2130-1
DLA-2298-1
DLA-3409-1
MGASA-2020-0129
OPENSUSE-SU-2020:0376-1
OPENSUSE-SU-2020_0376-1
RHSA-2020:3032
RHSA-2020:3970
RHSA-2020_3032
RHSA-2020_3970
RLSA-2020:3032
SUSE-SU-2020:0705-1
SUSE-SU-2020:0706-1
SUSE-SU-2020_0705-1
SUSE-SU-2020_0706-1
SUSE-SU-2025:4532-1

Affected Products

Almalinux
Centos
Red Hat
Rocky Linux
Suse
Mod Auth Openidc