Lucene search

K
redhatcveRedhat.comRH:CVE-2019-14857
HistoryOct 11, 2019 - 12:15 a.m.

CVE-2019-14857

2019-10-1100:15:54
redhat.com
access.redhat.com
10

0.001 Low

EPSS

Percentile

50.7%

An open redirect flaw was discovered in mod_auth_openidc, where it handles logout redirection. The module does not correctly validate the URL, allowing a URL with leading slashes to bypass the protection checks. A victim user may be tricked into visiting a trusted vulnerable web site, which would redirect them to another possibly malicious URL.