First published: Thu Feb 20 2020(Updated: )
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openidc Mod Auth Openidc | <2.4.1 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20479 is a vulnerability found in mod_auth_openidc before version 2.4.1.
The severity of CVE-2019-20479 is medium, with a severity value of 6.1.
The affected software includes Openidc Mod Auth Openidc before version 2.4.1, Debian Linux 8.0 and 9.0, Fedora 31 and 32, and openSUSE Leap 15.1.
The vulnerability in CVE-2019-20479 is an open redirect issue in URLs with a slash and backslash at the beginning.
To fix CVE-2019-20479, users should update to mod_auth_openidc version 2.4.1 or later.