mod_auth_openidc 是适用于 Apache 2.x HTTP 服务器的已获 OpenID 认证的认证与授权模块,实现了 OpenID Connect 依赖方(Relying Party)功能。在版本 2.4.19.4 之前,其状态cookie(state-cookie)解析器中存在缓冲区外读(out-of-bounds read)以及一个字节长的缓冲区外写(one-byte out-of-bounds write)漏洞。该问题已在版本 2.4.19.4 中得到修复,修复方式为在遇到字符串终止符时停止扫
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenIDC | mod_auth_openidc | < 2.4.19.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenIDC | mod_auth_openidc | < 2.4.19.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet