Known vulnerabilities in apache2-mod_auth_openidc
Vendor:
SUSE
Software:
apache2-mod_auth_openidc
Software CPE:
cpe:2.3:o:suse:apache2-mod_auth_openidc:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
12
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
2.4.17.1-150100.3.40.1
2.4.17.1-150600.16.20.1
2.4.0-7.25.1
2.4.17.1-150600.16.17.1
2.4.17.1-150100.3.37.1
2.4.17.1-150600.16.14.1
2.3.8-150100.3.34.1
2.3.8-150600.16.11.1
2.4.0-7.22.1
2.4.0-7.19.1
2.4.0-7.15.1
2.3.8-150100.3.31.1
2.3.8-150600.16.8.1
2.3.8-150600.16.5.1
2.3.8-150100.3.28.1
2.4.0-7.12.2
2.3.8-150100.3.25.1
2.3.8-150100.3.22.1
2.4.0-3.23.1
2.3.8-3.15.1
2.4.0-3.14.1
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU136688 - Out-of-bounds read CVE-2026-54789 |
CWE-125 | Medium | 2.4.0-7.25.1, 2.4.17.1-150100.3.40.1, 2.4.17.1-150600.16.20.1 | 02.07.2026 |
SB2026070228 SB2026071939 SB2026071940 and 6 more |
||
| #VU112073 - Improper input validation CVE-2025-3891 |
CWE-20 | Medium | 2.3.8-150100.3.34.1, 2.3.8-150600.16.11.1, 2.4.0-7.22.1 | 01.07.2025 |
SB2025070118 SB2025070119 SB2025070120 and 11 more |
||
| #VU107147 - Exposure of sensitive information to an unauthorized actor CVE-2025-31492 |
CWE-200 | Medium | 2.3.8-150100.3.31.1, 2.3.8-150600.16.8.1, 2.4.0-7.15.1, 2.4.0-7.19.1 | 08.04.2025 |
SB2025040831 SB2025040833 SB2025040834 and 22 more |
||
| #VU86531 - Resource exhaustion CVE-2024-24814 |
CWE-400 | Medium | 2.3.8-150100.3.28.1, 2.3.8-150600.16.5.1, 2.4.0-7.12.2 | 15.02.2024 |
SB2024021511 SB2024022245 SB2024030531 and 9 more |
||
| #VU79695 - Use of Externally-Controlled Format String CVE-2021-32785 |
CWE-134 | Medium | 2.3.8-3.15.1, 2.4.0-3.23.1 | 18.08.2023 |
SB2021072603 SB2021091342 SB2021101271 and 1 more |
||
| #VU79694 - Use of Insufficiently Random Values CVE-2021-32791 |
CWE-330 | Low | 2.3.8-3.15.1, 2.4.0-3.23.1 | 18.08.2023 |
SB2021072603 SB2023081884 SB2022051064 and 6 more |
||
| #VU79693 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2021-32786 |
CWE-601 | Low | 2.3.8-3.15.1, 2.4.0-3.23.1 | 18.08.2023 |
SB2021072603 SB2023081884 SB2022051064 and 6 more |
||
| #VU74352 - NULL Pointer Dereference CVE-2023-28625 |
CWE-476 | Medium | 2.3.8-150100.3.25.1 | 04.04.2023 |
SB2023040417 SB2023041466 SB2023051853 and 7 more |
||
| #VU71703 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2021-39191 |
CWE-601 | Low | 2.3.8-150100.3.22.1, 2.4.0-3.23.1 | 31.01.2023 |
SB2021090324 SB2023013118 SB2023081884 and 6 more |
||
| #VU70325 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2022-23527 |
CWE-601 | Low | 2.3.8-150100.3.22.1 | 14.12.2022 |
SB2022121429 SB2023013118 SB2023081884 and 9 more |
||
| #VU55291 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-32792 |
CWE-79 | Low | 2.3.8-3.15.1, 2.4.0-3.23.1 | 26.07.2021 |
SB2021072603 SB2023081884 SB2022051064 and 6 more |
||
| #VU53271 - Resource exhaustion CVE-2021-20718 |
CWE-400 | Medium | 2.4.0-3.14.1 | 14.05.2021 |
SB2021051410 SB2022012303 SB2021060950 and 2 more |