PT-2025-15122 · Unknown+10 · Mod Auth Openidc+10

Published

2025-04-06

·

Updated

2025-12-29

·

CVE-2025-31492

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mod auth openidc versions prior to 2.4.16.11
Description A bug in mod auth openidc results in disclosure of protected content to unauthenticated users. The conditions for disclosure include an OIDCProviderAuthRequestMethod POST, a valid account, and the absence of an application-level gateway or load balancer protecting the server. When requesting a protected resource, the response includes the HTTP status, HTTP headers, intended response, and protected resource without headers. The oidc content handler is called early but does not check for this specific case, leading to the handler returning DECLINED and httpd appending the protected content to the response.
Recommendations For mod auth openidc versions prior to 2.4.16.11, update to version 2.4.16.11 or later to resolve the issue. As a temporary workaround, consider restricting access to protected resources until the update can be applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALSA-2025:3997
ALSA-2025:7419
ALSA-2025:7490
ALT-PU-2025-13957
AZL-59592
AZL-61786
BDU:2025-11077
CESA-2025_3997
CVE-2025-31492
DLA-4129-1
DSA-5904-1
GHSA-59JP-RWPH-878R
INFSA-2025_3997
INFSA-2025_7419
MGASA-2025-0147
OESA-2025-1442
OESA-2025-1443
OESA-2025-1444
OESA-2025-1445
OPENSUSE-SU-2025:14972-1
OPENSUSE-SU-2025_1286-1
RHSA-2025:3945
RHSA-2025:3997
RHSA-2025:4128
RHSA-2025:4192
RHSA-2025:4224
RHSA-2025:4225
RHSA-2025:4227
RHSA-2025:4228
RHSA-2025:7419
RHSA-2025:7490
RHSA-2025_3997
RHSA-2025_7419
SUSE-SU-2025:1286-1
SUSE-SU-2025:1324-1
SUSE-SU-2025:1337-1
SUSE-SU-2025:1465-1
SUSE-SU-2025:4532-1
SUSE-SU-2025_1286-1
SUSE-SU-2025_1324-1
SUSE-SU-2025_1337-1
SUSE-SU-2025_1465-1
USN-7446-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Mod Auth Openidc