PT-2021-22446 · Apache+5 · Apache Http Server+5

Zandbelt

·

Published

2021-09-03

·

Updated

2025-12-29

·

CVE-2021-39191

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mod auth openidc versions prior to 2.4.9.4
Description The mod auth openidc module for the Apache 2.x HTTP server is vulnerable to an open redirect attack. This occurs when a crafted URL is supplied in the target link uri parameter, affecting the 3rd-party init SSO functionality. A patch in version 2.4.9.4 applies the OIDCRedirectURLsAllowed setting to the target link uri parameter, mitigating the issue.
Recommendations For mod auth openidc versions prior to 2.4.9.4, upgrade to a patched version, specifically version 2.4.9.4 or later, to resolve the issue. As a temporary workaround, consider restricting the use of the target link uri parameter until a patch is applied. Additionally, ensure the OIDCRedirectURLsAllowed setting is properly configured to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALSA-2022:1823
AZL-7289
CESA-2022_1823
CVE-2021-39191
DLA-3499-1
GHSA-2PGF-8H6H-GQG2
OPENSUSE-SU-2023_0215-1
RHSA-2022:1823
RHSA-2022_1823
RLSA-2022:1823
SUSE-SU-2021:3352-1
SUSE-SU-2023:0215-1
SUSE-SU-2023_0215-1
SUSE-SU-2025:4532-1

Affected Products

Almalinux
Apache Http Server
Centos
Red Hat
Rocky Linux
Suse