CVE-2021-32792: XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc
Published Jul 26, 2021
·Updated
modauthopenidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In modauthopenidc before version 2.4.9, there is an XSS vulnerability in when using OIDCPreservePost On.
Affected Software
4 affected components
openidc Mod Auth Openidc<2.4.9
Apache HTTP Server>=2.0.0<=2.4.48
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Patch Available
Event History
Jul 26, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-32792?
CVE-2021-32792 is an XSS vulnerability in mod_auth_openidc before version 2.4.9.
2
What is mod_auth_openidc?
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party.
3
How does mod_auth_openidc work?
mod_auth_openidc authenticates users against an OpenID Connect Provider.
4
What is the severity of CVE-2021-32792?
The severity of CVE-2021-32792 is medium (6.1).
5
How can I fix CVE-2021-32792?
To fix CVE-2021-32792, you should upgrade to mod_auth_openidc version 2.4.9.