Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.72% | — | Apache Http ServerAIMOD Auth OpenidcAI | 21/8/2026 | 18/9/2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is… | |
| Aplazada | Alta (8.2) | 0.57% | — | Apache MOD Auth OpenidcAIApache Http ServerAI | 6/4/2025 | 17/6/2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for… | |
| Modificada | Alta (7.5) | 1.3% | — | MOD Auth OpenidcDebian LinuxFedoraproject Fedora | 13/2/2024 | 17/6/2026 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of… | |
| Analizada | Alta (7.5) | 1.3% | — | MOD Auth Openidc | 3/4/2023 | 17/6/2026 | mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a… | |
| Modificada | Media (6.1) | 0.91% | — | MOD Auth OpenidcDebian Linux | 14/12/2022 | 17/6/2026 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that… | |
| Modificada | Media (6.1) | 1.7% | — | MOD Auth OpenidcFedoraproject FedoraDebian Linux | 3/9/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to… | |
| Modificada | Media (6.1) | 1.5% | — | MOD Auth OpenidcFedoraproject Fedora | 26/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`. | |
| Modificada | Media (5.9) | 1.5% | — | MOD Auth OpenidcFedoraproject Fedora | 26/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is… | |
| Modificada | Media (6.1) | 2.4% | — | MOD Auth OpenidcFedoraproject Fedora | 22/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs the same way as most browsers do. As a… | |
| Modificada | Alta (7.5) | 2.7% | — | MOD Auth OpenidcNetapp Cloud BackupDebian Linux | 22/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an unencrypted Redis cache (`OIDCCacheEncrypt off`,… | |
| Modificada | Alta (7.5) | 3.4% | — | MOD Auth OpenidcFedoraproject FedoraOracle Essbase | 20/5/2021 | 17/6/2026 | mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. | |
| Modificada | Media (6.1) | 1.9% | — | MOD Auth OpenidcDebian LinuxFedoraproject FedoraOpensuse Leap | 20/2/2020 | 17/6/2026 | A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. | |
| Modificada | Media (6.1) | 1.6% | — | MOD Auth Openidc | 26/11/2019 | 17/6/2026 | A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon. | |
| Modificada | Media (6.1) | 1.3% | — | MOD Auth Openidc | 19/7/2019 | 17/6/2026 | ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2. | |
| Modificada | Alta (7.5) | 5.2% | — | MOD Auth Openidc | 12/4/2017 | 17/6/2026 | Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request. | |
| Modificada | Alta (8.6) | 4.3% | — | MOD Auth Openidc | 2/3/2017 | 17/6/2026 | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic. | |
| Modificada | Alta (8.6) | 3.6% | — | MOD Auth Openidc | 2/3/2017 | 17/6/2026 | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic. | |
| Modificada | Baja (2.1) | 1.0% | — | Findingscience MOD Auth Openid | 25/7/2012 | 16/6/2026 | mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids. |