CVE-2019-20479: Medium severity mod_auth_openidc vulnerability
Published Feb 20, 2020
·Updated
A flaw was found in modauthopenidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
Affected Software
6 affected components
openidc Mod Auth Openidc<2.4.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Leap=15.1
Remediation
Patch Available
Event History
Feb 20, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2019-20479?
CVE-2019-20479 is a vulnerability found in mod_auth_openidc before version 2.4.1.
2
What is the severity of CVE-2019-20479?
The severity of CVE-2019-20479 is medium, with a severity value of 6.1.
3
What is the affected software for CVE-2019-20479?
The affected software includes Openidc Mod Auth Openidc before version 2.4.1, Debian Linux 8.0 and 9.0, Fedora 31 and 32, and openSUSE Leap 15.1.
4
What is the vulnerability in CVE-2019-20479?
The vulnerability in CVE-2019-20479 is an open redirect issue in URLs with a slash and backslash at the beginning.
5
How do I fix CVE-2019-20479?
To fix CVE-2019-20479, users should update to mod_auth_openidc version 2.4.1 or later.