Red Hat Bugzilla – Bug 1425350
CVE-2017-6059 mod_auth_openidc: Shows user-supplied content on error pages
Last modified: 2018-09-06 21:44:23 EDT
It was found that the OpenID Connect authentication module for Apache is vulnerable to Content Spoofing due to the user-supplied content being shown in the error pages. Upstream bug: https://github.com/pingidentity/mod_auth_openidc/issues/212 Upstream patch: https://github.com/pingidentity/mod_auth_openidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4
Created mod_auth_openidc tracking bugs for this issue: Affects: fedora-all [bug 1425356]