ELSA-2024-9180

ELSA-2024-9180 - mod_auth_openidc security update

Type:SECURITY
Severity:MODERATE
Release Date:2024-11-14

Description


[2.4.10-1]
Rebase to 2.4.10 version improves state cookies piling up problem
Resolves: RHEL-32450 Race condition in mod_auth_openidc filecache
Resolves: RHEL-25422 mod_auth_openidc: DoS when using
OIDCSessionType client-cookie and manipulating cookies
(CVE-2024-24814)


Related CVEs


CVE-2024-24814

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) mod_auth_openidc-2.4.10-1.el9.src.rpmfa6fbe9d1893fbd342802317786c3c9e-ol9_aarch64_appstream
mod_auth_openidc-2.4.10-1.el9.aarch64.rpmc9eeede3f5df2a184404d6696110657b-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) mod_auth_openidc-2.4.10-1.el9.src.rpmfa6fbe9d1893fbd342802317786c3c9e-ol9_x86_64_appstream
mod_auth_openidc-2.4.10-1.el9.x86_64.rpm4ad0e6c6fd83e1889378149f2dd8bb62-ol9_x86_64_appstream


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete