CVE-2017-6059: Input Validation
It was found that the OpenID Connect authentication module for Apache is vulnerable to Content Spoofing due to the user-supplied content being shown in the error pages.
Upstream bug:
https://github.com/pingidentity/modauthopenidc/issues/212
Upstream patch:
https://github.com/pingidentity/modauthopenidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4
Other sources
Modauthopenidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka modauthopenidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mod_auth_openidcto a version that resolves this vulnerability.Fixed in 2.1.4 - Upgrade
Upgrade
mod_auth_openidcto a version that resolves this vulnerability.Fixed in 2.14
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6059?
CVE-2017-6059 is classified as a medium severity vulnerability due to potential content spoofing risks.
How do I fix CVE-2017-6059?
To address CVE-2017-6059, update the mod_auth_openidc package to version 2.1.4 or later.
What systems are affected by CVE-2017-6059?
CVE-2017-6059 affects systems running mod_auth_openidc up to version 2.1.4.
What type of attack can CVE-2017-6059 allow?
CVE-2017-6059 can allow attackers to perform content spoofing attacks through manipulated error messages.
Is there a workaround for CVE-2017-6059?
There is no official workaround for CVE-2017-6059; updating the software is the recommended approach.