github OpenIDC/mod_auth_openidc v2.1.5
release 2.1.5

latest releases: v2.4.15.7, v2.4.15.6, v2.4.15.5...
7 years ago

This is a security release :

Those using AuthType openid-connect together with OIDCUnAuthAction pass on paths that disclose sensitive information based on the authenticated user are affected and should upgrade.

Security

On accessing paths protected with OIDCUnAuthAction pass no headers would be scrubbed when a user is not authenticated, so malicious software/users could set OIDC_CLAIM_ and OIDCAuthNHeader headers that applications would interpret as set by mod_auth_openidc even though the user has no authenticated session.

Bugfixes

  • fix error message about passing id_token with session type client-cookie; see: #220; thanks @phybros

Packaging Notes

Don't miss a new mod_auth_openidc release

NewReleases is sending notifications on new releases.