PT-2021-6452 · Unknown+5 · Mod Auth Openidc+5

Published

2021-06-10

·

Updated

2025-12-29

·

CVE-2021-32791

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mod auth openidc versions prior to 2.4.9
Description The issue is related to the AES GCM encryption in mod auth openidc, which uses a static IV and AAD. This creates a static nonce and can lead to known cryptographic issues since the same key is being reused. The problem allows a remote attacker to access confidential data.
Recommendations For mod auth openidc versions prior to 2.4.9, update to version 2.4.9 or later, which uses dynamic values through the usage of cjose AES encryption routines to fix the issue. As a temporary workaround, consider restricting access to sensitive data until the update can be applied.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

ALSA-2022:1823
AZL-6481
BDU:2022-01657
CESA-2022_1823
CVE-2021-32791
DLA-3409-1
GHSA-PX3C-6X7J-3R9R
MGASA-2021-0452
OPENSUSE-SU-2021:1277-1
OPENSUSE-SU-2021:3020-1
OPENSUSE-SU-2021_1277-1
OPENSUSE-SU-2021_3020-1
RHSA-2022:1823
RHSA-2022_1823
RLSA-2022:1823
SUSE-SU-2021:3020-1
SUSE-SU-2021:3352-1
SUSE-SU-2025:4532-1

Affected Products

Almalinux
Centos
Red Hat
Rocky Linux
Suse
Mod Auth Openidc