Mod Auth Openidc
Vendor:
First CVE: Mar 2, 2017 · Active for 9 years
15
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mod Auth Openidc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2017
9 years ago
Most Recent CVE
Feb 13, 2024
895 days ago
CVE Severity & Scoring
Mod Auth Openidc15 CVEs
53%
47%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None15 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6413HIGH The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader | Mar 2, 2017 | 8.6 | 29 | NO | NO |
CVE-2017-6062HIGH The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader | Mar 2, 2017 | 8.6 | 28 | NO | NO |
CVE-2017-6059HIGH Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malic | Apr 12, 2017 | 7.5 | 27 | NO | NO |
CVE-2021-20718HIGH mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. | May 20, 2021 | 7.5 | 26 | NO | NO |
CVE-2023-28625HIGH mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 thro | Apr 3, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-32785HIGH mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID | Jul 22, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-24814HIGH mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In a | Feb 13, 2024 | 7.5 | 23 | NO | NO |
CVE-2022-23527MEDIUM mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When pr | Dec 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-39191MEDIUM mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID | Sep 3, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-32792MEDIUM mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID | Jul 26, 2021 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Mod Auth Openidc
Top CWEs
Versions
No cataloged versions.