OpenIDC kayıtları
openidc üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')5
- CWE-287 Improper Authentication2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2017-6413İstismar yok | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does openidc · mod auth openidc · CWE-287 | Yüksek8,6 | — | %4,3 | 2 Mar 2017 |
35İzleyin | CVE-2017-6062İstismar yok | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does openidc · mod auth openidc · CWE-287 | Yüksek8,6 | — | %3,6 | 2 Mar 2017 |
32İzleyin | CVE-2017-6059İstismar yok | Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attopenidc · mod auth openidc · CWE-20 | Yüksek7,5 | — | %5,2 | 12 Nis 2017 |
31İzleyin | CVE-2021-20718İstismar yok | mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.openidc · mod auth openidc · CWE-400 | Yüksek7,5 | — | %3,4 | 19 May 2021 |
31İzleyin | CVE-2021-32785İstismar yok | Format string bug in the Redis cache implementationopenidc · mod auth openidc · CWE-134 | Yüksek7,5 | — | %2,7 | 22 Tem 2021 |
30İzleyin | CVE-2023-28625İstismar yok | mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is suppliedopenidc · mod auth openidc · CWE-476 | Yüksek7,5 | — | %1,3 | 3 Nis 2023 |
30İzleyin | CVE-2024-24814İstismar yok | Denial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidcopenidc · mod auth openidc · CWE-400 | Yüksek7,5 | — | %1,3 | 13 Şub 2024 |
25İzleyin | CVE-2021-32786İstismar yok | Open Redirect in oidc_validate_redirect_url()openidc · mod auth openidc · CWE-601 | Orta6,1 | — | %2,4 | 22 Tem 2021 |
25İzleyin | CVE-2019-20479İstismar yok | A flaw was found in mod_auth_openidc before version 2.4.1.openidc · mod auth openidc · CWE-601 | Orta6,1 | — | %1,9 | 20 Şub 2020 |
25İzleyin | CVE-2021-39191İstismar yok | URL Redirection to Untrusted Site ('Open Redirect') in mod_auth_openidcopenidc · mod auth openidc · CWE-601 | Orta6,1 | — | %1,7 | 3 Eyl 2021 |
24İzleyin | CVE-2019-14857İstismar yok | A flaw was found in mod_auth_openidc before version 2.4.0.1.openidc · mod auth openidc · CWE-601 | Orta6,1 | — | %1,6 | 26 Kas 2019 |
24İzleyin | CVE-2021-32792İstismar yok | XSS vulnerability when using OIDCPreservePost On in mod_auth_openidcopenidc · mod auth openidc · CWE-79 | Orta6,1 | — | %1,5 | 26 Tem 2021 |
24İzleyin | CVE-2019-1010247İstismar yok | ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS).openidc · mod auth openidc · CWE-79 | Orta6,1 | — | %1,3 | 19 Tem 2019 |
24İzleyin | CVE-2022-23527İstismar yok | Open Redirect in oidc_validate_redirect_url()openidc · mod auth openidc · CWE-601 | Orta6,1 | — | %0,9 | 14 Ara 2022 |
23İzleyin | CVE-2021-32791İstismar yok | Hardcoded static IV and AAD with a reused key in AES GCM encryption in mod_auth_openidcopenidc · mod auth openidc · CWE-323 | Orta5,9 | — | %1,5 | 26 Tem 2021 |
- CVE-2017-641335İzleyin
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does
YüksekCVSS 8,6İstismar yokEPSS %4openidc · mod auth openidc2 Mar 2017
- CVE-2017-606235İzleyin
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does
YüksekCVSS 8,6İstismar yokEPSS %4openidc · mod auth openidc2 Mar 2017
- CVE-2017-605932İzleyin
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote att
YüksekCVSS 7,5İstismar yokEPSS %5openidc · mod auth openidc12 Nis 2017
- CVE-2021-2071831İzleyin
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
YüksekCVSS 7,5İstismar yokEPSS %3openidc · mod auth openidc19 May 2021
- CVE-2021-3278531İzleyin
Format string bug in the Redis cache implementation
YüksekCVSS 7,5İstismar yokEPSS %3openidc · mod auth openidc22 Tem 2021
- CVE-2023-2862530İzleyin
mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied
YüksekCVSS 7,5İstismar yokEPSS %1openidc · mod auth openidc3 Nis 2023
- CVE-2024-2481430İzleyin
Denial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidc
YüksekCVSS 7,5İstismar yokEPSS %1openidc · mod auth openidc13 Şub 2024
- CVE-2021-3278625İzleyin
Open Redirect in oidc_validate_redirect_url()
OrtaCVSS 6,1İstismar yokEPSS %2openidc · mod auth openidc22 Tem 2021
- CVE-2019-2047925İzleyin
A flaw was found in mod_auth_openidc before version 2.4.1.
OrtaCVSS 6,1İstismar yokEPSS %2openidc · mod auth openidc20 Şub 2020
- CVE-2021-3919125İzleyin
URL Redirection to Untrusted Site ('Open Redirect') in mod_auth_openidc
OrtaCVSS 6,1İstismar yokEPSS %2openidc · mod auth openidc3 Eyl 2021
- CVE-2019-1485724İzleyin
A flaw was found in mod_auth_openidc before version 2.4.0.1.
OrtaCVSS 6,1İstismar yokEPSS %2openidc · mod auth openidc26 Kas 2019
- CVE-2021-3279224İzleyin
XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc
OrtaCVSS 6,1İstismar yokEPSS %2openidc · mod auth openidc26 Tem 2021
- CVE-2019-101024724İzleyin
ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1openidc · mod auth openidc19 Tem 2019
- CVE-2022-2352724İzleyin
Open Redirect in oidc_validate_redirect_url()
OrtaCVSS 6,1İstismar yokEPSS %1openidc · mod auth openidc14 Ara 2022
- CVE-2021-3279123İzleyin
Hardcoded static IV and AAD with a reused key in AES GCM encryption in mod_auth_openidc
OrtaCVSS 5,9İstismar yokEPSS %2openidc · mod auth openidc26 Tem 2021