Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-32792

22
FAUCET Score

CVE-2021-32792 describes a Cross-Site Scripting (XSS) vulnerability in mod_auth_openidc, an Apache module for OpenID Connect authentication, specifically when the OIDCPreservePost On directive is enabled. This medium-severity vulnerability (CVSS 6.1) can be exploited remotely with low attack complexity, requiring user interaction, and could lead to limited confidentiality and integrity impacts. While the vulnerability affects various Apache and Fedora products utilizing mod_auth_openidc, there is currently no evidence of active exploitation, public exploit code, or significant community discussion beyond a single mention.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.9CPE matchmatch criteria
cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.52%
Probability of exploitation in next 30 days
EPSS Percentile
72.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0152 is in the 84th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 httpd 2.4.52-1 on CBL Mariner 2.0Fixed in: 2.4.52-1
microsoftpatch availablevia msrc
Product: 17030-16823Fixed in: 2.4.52-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.4.52-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.4.52-1
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mod_auth_openidc:2.3-8060020220131105504.d63f516d
View patch

Vendor Advisories (3)

microsoft2021-Dec/CVE-2021-32792

CVE-2021-32792

Dec 14, 2021
redhatCVE-2021-32792Moderate

mod_auth_openidc: XSS when using OIDCPreservePost On

Jul 24, 2021
microsoft2021-Jul/CVE-2021-32792Moderate

XSS vulnerability when using OIDCPreservePost On in mod_auth_openidc

Jul 13, 2021

References

github.com / zmartzone/mod_auth_openidc/commit/00c315cb0c8ab77c67be4a2ac08a71a83ac58751
PatchThird Party Advisory
github.com / zmartzone/mod_auth_openidc/commit/55ea0a085290cd2c8cdfdd960a230cbc38ba8b56
PatchThird Party Advisory
github.com / zmartzone/mod_auth_openidc/releases/tag/v2.4.9
Release NotesThird Party Advisory
github.com / zmartzone/mod_auth_openidc/security/advisories/GHSA-458c-7pwg-3j7j
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2023/04/msg00034.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FZVF6BSJLRQZ7PFFR4X5JSU6KUJYNOCU
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QXAWKPT5LXZSUTFSJ6IWSZC7RMYYQXQD
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory