It was found that the OpenID Connect authentication module for Apache is vulnerable to Content Spoofing due to the user-supplied content being shown in the error pages. Upstream bug: https://github.com/pingidentity/mod_auth_openidc/issues/212 Upstream patch: https://github.com/pingidentity/mod_auth_openidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4
Created mod_auth_openidc tracking bugs for this issue: Affects: fedora-all [bug 1425356]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2112 https://access.redhat.com/errata/RHSA-2019:2112