CVE-2019-14857 – mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes
https://notcve.org/view.php?id=CVE-2019-14857
A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon. Se encontró una fallo en mod_auth_openidc anterior de la versión 2.4.0.1. Existe un problema de redireccionamiento abierto en las URL con barras diagonales en mod_auth_mellon. An open redirect flaw was discovered in mod_auth_openidc, where it handles logout redirection. • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14857 https://github.com/zmartzone/mod_auth_openidc/commit/5c15dfb08106c2451c2c44ce7ace6813c216ba75 https://github.com/zmartzone/mod_auth_openidc/commit/ce37080c6aea30aabae8b4a9b4eea7808445cc8e https://github.com/zmartzone/mod_auth_openidc/pull/451 https://groups.google.com/forum/#%21topic/mod_auth_openidc/boy1Ba3Gdk4 https://lists.debian.org/debian-lts-announce/2020/07/msg00028.html https://access.redhat.com/security/cve/CVE-2019-14857 https://bugzilla • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •