Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38543
HistoryDec 20, 2022 - 9:04 a.m.

Open Redirect

2022-12-2009:04:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
open redirect
software
apache

0.001 Low

EPSS

Percentile

42.0%

libapache2-mod-auth-openidc is vulnerable to open redirect. When provided with a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that start with /\t, leading to an open redirect.