[ Все 3 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z ]
×

Проект mod_auth_openidc-2.4.9.4-7.module+el8.10.0+622+0135de12

Имя mod_auth_openidc
Эпоха 0
Версия 2.4.9.4
Релиз 7.module+el8.10.0+622+0135de12
Сайт https://github.com/zmartzone/mod_auth_openidc
Лицензия ASL 2.0
Время сборки 2025-04-18 10:41:29
Хост сборки builder-x86-08.inferitos.ru
Краткое описание OpenID Connect auth module for Apache HTTP Server
Репозитории AppStream
Полное описание This module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.
Эррата INFSA-2025:3997
Module mod_auth_openidc-2.3-8100020250418071814.acbbbf20
× Full screenshot
Пакеты link
Пакет Краткое описание Контрольная сумма SHA-256
x86_64
mod_auth_openidc-2.4.9.4-7.module+el8.10.0+622+0135de12.x86_64 OpenID Connect auth module for Apache HTTP Server 05bddbf4cda8fc1a55dbaf79dcfc4b10d24f8974c95634772fa1f8f4cd150f2c download
src
mod_auth_openidc-2.4.9.4-7.module+el8.10.0+622+0135de12.src OpenID Connect auth module for Apache HTTP Server ae7ab0dadf63f97f0c05b3462fbc53453161a392e1084f60ab34f3550a69ea37 download
История изменений link
* Fri Apr 11 2025 Tomas Halman <thalman@redhat.com> - 2.4.9.4-7
- Resolves: RHEL-86218 - mod_auth_openidc allows OIDCProviderAuthRequestMethod
            POSTs to leak protected data (CVE-2025-31492)

* Fri Apr 12 2024 Tomas Halman <thalman@redhat.com> - 2.4.9.4-6
- Resolves: RHEL-36492 Race condition in mod_auth_openidc filecache
- Resolves: RHEL-25421 mod_auth_openidc: DoS when using
    `OIDCSessionType client-cookie` and manipulating cookies
    (CVE-2024-24814)

* Sun Dec 10 2023 MSVSphere Packaging Team <packager@msvsphere-os.ru> - 2.4.9.4-5
- Rebuilt for MSVSphere 8.8

* Tue Apr 25 2023 Tomas Halman <thalman@redhat.com> - 2.4.9.4-5
Related: rhbz#2141850 - fix cjose version dependency

* Mon Apr 24 2023 Tomas Halman <thalman@redhat.com> - 2.4.9.4-4
Resolves: rhbz#2141850 - auth_openidc.conf mode 0640 by default

* Tue Apr 11 2023 Tomas Halman <thalman@redhat.com> - 2.4.9.4-3
- Resolves: rhbz#2184144 - CVE-2023-28625 NULL pointer dereference
      when OIDCStripCookies is set and a crafted Cookie header is supplied

* Tue Feb 21 2023 Tomas Halman <thalman@redhat.com> - 2.4.9.4-2
- Resolves: rhbz#2153659 - CVE-2022-23527 - Open Redirect in
      oidc_validate_redirect_url() using tab character

* Fri Apr 08 2022 Tomas Halman <thalman@redhat.com> - 2.4.9.4-1
- Resolves: rhbz#2025368 - Rebase to new version

* Fri Jan 28 2022 Tomas Halman <thalman@redhat.com> - 2.3.7-11
- Resolves: rhbz#1987222 - CVE-2021-32792 XSS when using OIDCPreservePost On

* Fri Jan 28 2022 Tomas Halman <thalman@redhat.com> - 2.3.7-10
- Resolves: rhbz#1987216 - CVE-2021-32791 hardcoded static IV and AAD with a
                           reused key in AES GCM encryption [rhel-8] (edit)