First published: Sun Apr 06 2025(Updated: )
Last updated 9 April 2025
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenID mod_auth_openidc | <=2.4.16.11 | |
debian/libapache2-mod-auth-openidc | <=2.4.9.4-0+deb11u4<=2.4.12.3-2+deb12u2 | 2.4.9.4-0+deb11u5 2.4.12.3-2+deb12u3 2.4.16.11-1 2.4.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31492 is considered a critical vulnerability due to its potential to disclose protected content to unauthenticated users.
To fix CVE-2025-31492, upgrade the mod_auth_openidc module to version 2.4.16.11 or later.
CVE-2025-31492 affects versions of the mod_auth_openidc module prior to 2.4.16.11 on the Apache 2.x HTTP server.
CVE-2025-31492 is a security vulnerability related to unauthorized access to protected content.
It is the responsibility of users and administrators of the affected software to apply the necessary updates to mitigate CVE-2025-31492.