4.3
CVSSv2

CVE-2021-32792

Published: 26/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openidc mod_auth_openidc

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #991580 libapache2-mod-auth-openidc: CVE-2021-32792 Package: src:libapache2-mod-auth-openidc; Maintainer for src:libapache2-mod-auth-openidc is Moritz Schlarb <schlarbm@uni-mainzde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 27 Jul 2021 20:06:01 UTC Severity: important ...
mod_auth_openidc is an authentication/authorization module for the Apache 2x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider In mod_auth_openidc before version 249, there is an XSS vulnerability in when using `OIDCPreservePost On` ...