PT-2021-22446 · Apache+5 · Apache Http Server+5
Zandbelt
·
Published
2021-09-03
·
Updated
2025-12-29
·
CVE-2021-39191
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mod auth openidc versions prior to 2.4.9.4
Description
The mod auth openidc module for the Apache 2.x HTTP server is vulnerable to an open redirect attack. This occurs when a crafted URL is supplied in the
target link uri parameter, affecting the 3rd-party init SSO functionality. A patch in version 2.4.9.4 applies the OIDCRedirectURLsAllowed setting to the target link uri parameter, mitigating the issue.Recommendations
For mod auth openidc versions prior to 2.4.9.4, upgrade to a patched version, specifically version 2.4.9.4 or later, to resolve the issue. As a temporary workaround, consider restricting the use of the
target link uri parameter until a patch is applied. Additionally, ensure the OIDCRedirectURLsAllowed setting is properly configured to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Apache Http Server
Centos
Red Hat
Rocky Linux
Suse