Openidc is a narrowly scoped OpenID Connect authentication module (mod_auth_openidc) that provides protocol-level access control across a range of web applications and services. Its vulnerability exposure centers on authentication and request-handling logic, with recurrent weaknesses including open redirects, improper authentication enforcement, cross-site scripting, resource exhaustion, and input validation gaps—flaws characteristic of protocol implementations bridging external identity providers and protected web resources. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openidc over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6413HIGH The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader | Mar 2, 2017 | 8.6 | 29 | NO | NO |
CVE-2017-6062HIGH The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader | Mar 2, 2017 | 8.6 | 28 | NO | NO |
CVE-2017-6059HIGH Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malic | Apr 12, 2017 | 7.5 | 27 | NO | NO |
CVE-2021-20718HIGH mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. | May 20, 2021 | 7.5 | 26 | NO | NO |
CVE-2023-28625HIGH mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 thro | Apr 3, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-32785HIGH mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID | Jul 22, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-24814HIGH mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In a | Feb 13, 2024 | 7.5 | 23 | NO | NO |
CVE-2022-23527MEDIUM mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When pr | Dec 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-39191MEDIUM mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID | Sep 3, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-32792MEDIUM mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID | Jul 26, 2021 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openidc.
Media articles that mention a CVE ID that affects a product developed by Openidc — matched by CVE ID, not by vendor name.