An unauthenticated attacker can crash the Apache httpd process by sending an empty POST request when OIDCPreservePost is enabled in mod_auth_openidc. This leads to denial of service.
Hi Can you share details about this CVE assiignment? According to the Debian maintainer and upstream of the project they were not informed about this issue and as well cannot reproduce crashes, cf. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1104484#10 Can you please elaborate? Regards, Salvatore