Red Hat Bugzilla – Bug 1425353
CVE-2017-6062 mod_auth_openidc: OIDCUnAuthAction pass does not scrub request headers
Last modified: 2018-09-06 21:44:55 EDT
It was found that when OIDCUnAuthAction is set to pass the OICD_CLAIM_* headers are not being scrubbed. This allows for unauthenticated requests to /content/. Sending the OIDC_CLAIM_preferred_username header then allows to spoof any existing username. Upstream bug: https://github.com/pingidentity/mod_auth_openidc/issues/222 Upstream patch: https://github.com/pingidentity/mod_auth_openidc/commit/e81822a7d5f5bdf04ba03ca92680821893303850
Created mod_auth_openidc tracking bugs for this issue: Affects: fedora-all [bug 1425356]