Inclusion of Sensitive Information in Log Files in mod_auth_openidc - #VU142427

 

Inclusion of Sensitive Information in Log Files in mod_auth_openidc - #VU142427

Published: August 13, 2026


Vulnerability identifier: #VU142427
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive credentials from debug logs.

The vulnerability exists due to insertion of sensitive information into log files in debug logging of provider responses and cookie values when writing unredacted response data to logs. A local user can read debug logs to disclose sensitive credentials from debug logs.

This includes tokens, client secrets, registration access tokens, and cookie values, and requires debug logging and log access.


Affected software

mod_auth_openidc

Remediation

Install security update from vendor's website.

mod_auth_openidc - update to 2.4.20.1

External References

Related Security Bulletins