USN-7446-1: mod_auth_openidc vulnerability
Published Apr 23, 2025
·Updated
It was discovered that modauthopenidc incorrectly handled certain POST requests. An attacker could possibly use this issue to obtain sensitive information.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/libapache2-mod-auth-openidc<2.4.16.10-1ubuntu1
2.4.16.10-1ubuntu1
Ubuntu Ubuntu=25.04
All of the following
ubuntu/libapache2-mod-auth-openidc<2.4.15.7-2ubuntu0.1
2.4.15.7-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/libapache2-mod-auth-openidc<2.4.15.1-1ubuntu0.1
2.4.15.1-1ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libapache2-mod-auth-openidc<2.4.11-1ubuntu0.1
2.4.11-1ubuntu0.1
Ubuntu Ubuntu=22.04
Event History
Apr 23, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7446-1?
The severity of USN-7446-1 is categorized as a medium vulnerability.
2
How do I fix USN-7446-1?
To fix USN-7446-1, upgrade the libapache2-mod-auth-openidc package to the latest recommended version for your Ubuntu release.
3
What does USN-7446-1 affect?
USN-7446-1 affects the libapache2-mod-auth-openidc package on specific versions of Ubuntu.
4
What vulnerability is documented in USN-7446-1?
USN-7446-1 documents a vulnerability where mod_auth_openidc incorrectly handled certain POST requests, potentially exposing sensitive information.
5
Is my system vulnerable due to USN-7446-1?
If you are using an affected version of libapache2-mod-auth-openidc on Ubuntu, your system is vulnerable to USN-7446-1.