PT-2025-15122 · Unknown+10 · Mod Auth Openidc+10
Published
2025-04-06
·
Updated
2025-12-29
·
CVE-2025-31492
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mod auth openidc versions prior to 2.4.16.11
Description
A bug in mod auth openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure include an OIDCProviderAuthRequestMethod
POST, a valid account, and the absence of an application-level gateway or load balancer protecting the server. When requesting a protected resource, the response includes the HTTP status, HTTP headers, intended response, and protected resource without headers. The oidc content handler is called early but does not check for this specific case, leading to the handler returning DECLINED and httpd appending the protected content to the response.Recommendations
For mod auth openidc versions prior to 2.4.16.11, update to version 2.4.16.11 or later to resolve the issue. As a temporary workaround, consider restricting access to protected resources until the update can be applied.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Mod Auth Openidc