ELSA-2024-9180 - mod_auth_openidc security update
Type: | SECURITY |
Severity: | MODERATE |
Release Date: | 2024-11-14 |
Description
[2.4.10-1]
Rebase to 2.4.10 version improves state cookies piling up problem
Resolves: RHEL-32450 Race condition in mod_auth_openidc filecache
Resolves: RHEL-25422 mod_auth_openidc: DoS when using
OIDCSessionType client-cookie and manipulating cookies
(CVE-2024-24814)
Related CVEs
Updated Packages
Release/Architecture | Filename | MD5sum | Superseded By Advisory | Channel Label |
|
Oracle Linux 9 (aarch64) | mod_auth_openidc-2.4.10-1.el9.src.rpm | fa6fbe9d1893fbd342802317786c3c9e | - | ol9_aarch64_appstream |
| mod_auth_openidc-2.4.10-1.el9.aarch64.rpm | c9eeede3f5df2a184404d6696110657b | - | ol9_aarch64_appstream |
|
Oracle Linux 9 (x86_64) | mod_auth_openidc-2.4.10-1.el9.src.rpm | fa6fbe9d1893fbd342802317786c3c9e | - | ol9_x86_64_appstream |
| mod_auth_openidc-2.4.10-1.el9.x86_64.rpm | 4ad0e6c6fd83e1889378149f2dd8bb62 | - | ol9_x86_64_appstream |