PT-2021-6452 · Unknown+5 · Mod Auth Openidc+5
Published
2021-06-10
·
Updated
2025-12-29
·
CVE-2021-32791
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mod auth openidc versions prior to 2.4.9
Description
The issue is related to the AES GCM encryption in mod auth openidc, which uses a static IV and AAD. This creates a static nonce and can lead to known cryptographic issues since the same key is being reused. The problem allows a remote attacker to access confidential data.
Recommendations
For mod auth openidc versions prior to 2.4.9, update to version 2.4.9 or later, which uses dynamic values through the usage of cjose AES encryption routines to fix the issue. As a temporary workaround, consider restricting access to sensitive data until the update can be applied.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Mod Auth Openidc