Lucene search

K
redhatcveRedhat.comRH:CVE-2019-20479
HistoryFeb 20, 2020 - 9:44 a.m.

CVE-2019-20479

2020-02-2009:44:26
redhat.com
access.redhat.com
11

0.003 Low

EPSS

Percentile

68.9%

An open redirect flaw was discovered in mod_auth_openidc where it handles logout redirection. The module does not correctly validate the URL, allowing a URL with slash and backslash at the beginning to bypass the protection checks. A victim user may be tricked into visiting a trusted vulnerable web site, which would redirect him to another, possibly malicious, URL.