Known vulnerabilities in apache2-mod_auth_openidc

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:apache2-mod_auth_openidc:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting apache2-mod_auth_openidc apache2-mod_auth_openidc is affected by 12 known vulnerabilities: 7 medium, 5 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136688 - Out-of-bounds read
CVE-2026-54789
CWE-125 Medium
No
No
2.4.0-7.25.1, 2.4.17.1-150100.3.40.1, 2.4.17.1-150600.16.20.1 02.07.2026 SB2026070228
SB2026071939
SB2026071940
and 6 more
#VU112073 - Improper input validation
CVE-2025-3891
CWE-20 Medium
No
No
2.3.8-150100.3.34.1, 2.3.8-150600.16.11.1, 2.4.0-7.22.1 01.07.2025 SB2025070118
SB2025070119
SB2025070120
and 11 more
#VU107147 - Exposure of sensitive information to an unauthorized actor
CVE-2025-31492
CWE-200 Medium
No
No
2.3.8-150100.3.31.1, 2.3.8-150600.16.8.1, 2.4.0-7.15.1, 2.4.0-7.19.1 08.04.2025 SB2025040831
SB2025040833
SB2025040834
and 22 more
#VU86531 - Resource exhaustion
CVE-2024-24814
CWE-400 Medium
No
No
2.3.8-150100.3.28.1, 2.3.8-150600.16.5.1, 2.4.0-7.12.2 15.02.2024 SB2024021511
SB2024022245
SB2024030531
and 9 more
#VU79695 - Use of Externally-Controlled Format String
CVE-2021-32785
CWE-134 Medium
No
No
2.3.8-3.15.1, 2.4.0-3.23.1 18.08.2023 SB2021072603
SB2021091342
SB2021101271
and 1 more
#VU79694 - Use of Insufficiently Random Values
CVE-2021-32791
CWE-330 Low
No
No
2.3.8-3.15.1, 2.4.0-3.23.1 18.08.2023 SB2021072603
SB2023081884
SB2022051064
and 6 more
#VU79693 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-32786
CWE-601 Low
No
No
2.3.8-3.15.1, 2.4.0-3.23.1 18.08.2023 SB2021072603
SB2023081884
SB2022051064
and 6 more
#VU74352 - NULL Pointer Dereference
CVE-2023-28625
CWE-476 Medium
No
No
2.3.8-150100.3.25.1 04.04.2023 SB2023040417
SB2023041466
SB2023051853
and 7 more
#VU71703 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-39191
CWE-601 Low
No
No
2.3.8-150100.3.22.1, 2.4.0-3.23.1 31.01.2023 SB2021090324
SB2023013118
SB2023081884
and 6 more
#VU70325 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-23527
CWE-601 Low
No
No
2.3.8-150100.3.22.1 14.12.2022 SB2022121429
SB2023013118
SB2023081884
and 9 more
#VU55291 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-32792
CWE-79 Low
No
No
2.3.8-3.15.1, 2.4.0-3.23.1 26.07.2021 SB2021072603
SB2023081884
SB2022051064
and 6 more
#VU53271 - Resource exhaustion
CVE-2021-20718
CWE-400 Medium
No
No
2.4.0-3.14.1 14.05.2021 SB2021051410
SB2022012303
SB2021060950
and 2 more