Synopsis
Moderate: mod_auth_openidc security and bug fix update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for mod_auth_openidc is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.
Security Fix(es):
- mod_auth_openidc: Open Redirect in oidc_validate_redirect_url() using tab character (CVE-2022-23527)
- mod_auth_openidc: NULL pointer dereference when OIDCStripCookies is set and a crafted Cookie header is supplied (CVE-2023-28625)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.3 Release Notes linked from the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.4 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
Fixes
-
BZ - 2153655
- CVE-2022-23527 mod_auth_openidc: Open Redirect in oidc_validate_redirect_url() using tab character
-
BZ - 2184118
- CVE-2023-28625 mod_auth_openidc: NULL pointer dereference when OIDCStripCookies is set and a crafted Cookie header is supplied
-
BZ - 2189268
- auth_openidc.conf probably should be mode 0640 by default
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
x86_64 |
mod_auth_openidc-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: ce28413ba72570859f38ce7f7b8c51ea4207a46337ee8b0f2f7b044767092f77 |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: a5c8afc14998f144b46ba425cda69aa6add8c303f76b6d08878518910ed3cb1c |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: f92a03e0bad645089d7fd53e1c27cbcbece847a742fd8e1c3300db1b2e79d7b8 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
x86_64 |
mod_auth_openidc-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: ce28413ba72570859f38ce7f7b8c51ea4207a46337ee8b0f2f7b044767092f77 |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: a5c8afc14998f144b46ba425cda69aa6add8c303f76b6d08878518910ed3cb1c |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: f92a03e0bad645089d7fd53e1c27cbcbece847a742fd8e1c3300db1b2e79d7b8 |
Red Hat Enterprise Linux Server - AUS 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
x86_64 |
mod_auth_openidc-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: ce28413ba72570859f38ce7f7b8c51ea4207a46337ee8b0f2f7b044767092f77 |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: a5c8afc14998f144b46ba425cda69aa6add8c303f76b6d08878518910ed3cb1c |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: f92a03e0bad645089d7fd53e1c27cbcbece847a742fd8e1c3300db1b2e79d7b8 |
Red Hat Enterprise Linux for IBM z Systems 9
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
s390x |
mod_auth_openidc-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: 21c2b7f264eb44a667a9d4b54bc5b7b49bf4191f3d30d9e9e5d520ea8982bfcb |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: c0536038e8f6554a48ca14d92c0bf477a1ab9435e37273368563d47c7306c361 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: 0c390f29dd8e84211f7a2b48cb4b6e9a14645fa6c31f6be5366ba2b60cde0723 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
s390x |
mod_auth_openidc-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: 21c2b7f264eb44a667a9d4b54bc5b7b49bf4191f3d30d9e9e5d520ea8982bfcb |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: c0536038e8f6554a48ca14d92c0bf477a1ab9435e37273368563d47c7306c361 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: 0c390f29dd8e84211f7a2b48cb4b6e9a14645fa6c31f6be5366ba2b60cde0723 |
Red Hat Enterprise Linux for Power, little endian 9
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
ppc64le |
mod_auth_openidc-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 80335d5fcf7dd0971469987dd21988dfe3b11df10bbae32c85a1602c7c280b5b |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 7825a4fc9a39115c7e0287c30419aa195d4450b56ecf55585911a72be1104489 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 5657b14b872dcb20a2e219face9c3ad9ec7979a43577faa4edca9f44a4de15a4 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
ppc64le |
mod_auth_openidc-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 80335d5fcf7dd0971469987dd21988dfe3b11df10bbae32c85a1602c7c280b5b |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 7825a4fc9a39115c7e0287c30419aa195d4450b56ecf55585911a72be1104489 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 5657b14b872dcb20a2e219face9c3ad9ec7979a43577faa4edca9f44a4de15a4 |
Red Hat Enterprise Linux for ARM 64 9
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
aarch64 |
mod_auth_openidc-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: 3b40839338010766faca6910012f5d5f0a3d78b28a08d7efddee1de7fb6cdf6b |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: d6a74831d915e476d15fe9484485217a276ebd74dbd3bef5dc6605bb3e54ceb1 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: faceaff9e9918b9812a1d5255d350b136c40fa817724abae4670181cb318104c |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
aarch64 |
mod_auth_openidc-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: 3b40839338010766faca6910012f5d5f0a3d78b28a08d7efddee1de7fb6cdf6b |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: d6a74831d915e476d15fe9484485217a276ebd74dbd3bef5dc6605bb3e54ceb1 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: faceaff9e9918b9812a1d5255d350b136c40fa817724abae4670181cb318104c |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
ppc64le |
mod_auth_openidc-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 80335d5fcf7dd0971469987dd21988dfe3b11df10bbae32c85a1602c7c280b5b |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 7825a4fc9a39115c7e0287c30419aa195d4450b56ecf55585911a72be1104489 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.ppc64le.rpm
|
SHA-256: 5657b14b872dcb20a2e219face9c3ad9ec7979a43577faa4edca9f44a4de15a4 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
x86_64 |
mod_auth_openidc-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: ce28413ba72570859f38ce7f7b8c51ea4207a46337ee8b0f2f7b044767092f77 |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: a5c8afc14998f144b46ba425cda69aa6add8c303f76b6d08878518910ed3cb1c |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.x86_64.rpm
|
SHA-256: f92a03e0bad645089d7fd53e1c27cbcbece847a742fd8e1c3300db1b2e79d7b8 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
aarch64 |
mod_auth_openidc-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: 3b40839338010766faca6910012f5d5f0a3d78b28a08d7efddee1de7fb6cdf6b |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: d6a74831d915e476d15fe9484485217a276ebd74dbd3bef5dc6605bb3e54ceb1 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.aarch64.rpm
|
SHA-256: faceaff9e9918b9812a1d5255d350b136c40fa817724abae4670181cb318104c |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4
SRPM |
mod_auth_openidc-2.4.9.4-4.el9.src.rpm
|
SHA-256: fb795f539152df9cbb5f4edf4492f415db11f4f470aa1bdb2aa740e6d3c195b4 |
s390x |
mod_auth_openidc-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: 21c2b7f264eb44a667a9d4b54bc5b7b49bf4191f3d30d9e9e5d520ea8982bfcb |
mod_auth_openidc-debuginfo-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: c0536038e8f6554a48ca14d92c0bf477a1ab9435e37273368563d47c7306c361 |
mod_auth_openidc-debugsource-2.4.9.4-4.el9.s390x.rpm
|
SHA-256: 0c390f29dd8e84211f7a2b48cb4b6e9a14645fa6c31f6be5366ba2b60cde0723 |