Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-6062
HistoryMar 02, 2017 - 6:59 a.m.

Authentication flaw

2017-03-0206:59:00
PRIOn knowledge base
www.prio-n.com
6

8.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.9%

The “OpenID Connect Relying Party and OAuth 2.0 Resource Server” (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an “OIDCUnAuthAction pass” configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.

CPENameOperatorVersion
mod_auth_openidcle2.1.4

8.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.9%