CVE-2017-6059

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/04/2017
Last modified:
07/11/2023

Description

Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:* 2.1.4 (excluding)