Lucene search

K
osvGoogleOSV:CVE-2017-6062
HistoryMar 02, 2017 - 6:59 a.m.

CVE-2017-6062

2017-03-0206:59:00
Google
osv.dev
9

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

61.9%

The “OpenID Connect Relying Party and OAuth 2.0 Resource Server” (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an “OIDCUnAuthAction pass” configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

61.9%