First published: Tue Apr 22 2025(Updated: )
An unauthenticated attacker can crash the Apache httpd process by sending an empty POST request when OIDCPreservePost is enabled in mod_auth_openidc. This leads to denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | ||
OpenID mod_auth_openidc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2361633 is classified as a denial of service vulnerability.
Apache HTTP Server and mod_auth_openidc users with OIDCPreservePost enabled are impacted by REDHAT-BUG-2361633.
REDHAT-BUG-2361633 allows an unauthenticated attacker to crash the Apache httpd process by sending an empty POST request.
To fix REDHAT-BUG-2361633, disable OIDCPreservePost in the mod_auth_openidc configuration.
Immediately review your Apache httpd configuration and consider disabling OIDCPreservePost to mitigate the vulnerability.