#VU86531 Resource exhaustion in mod_auth_openidc - CVE-2024-24814
Published: February 15, 2024
mod_auth_openidc
ZmartZone IAM
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling a vaery large mod_auth_openidc_session_chunks cookie value. A remote attacker can set the cookie to value 99999999 or higher, trigger resource exhaustion and perform a denial of service (DoS) attack.