It was discovered that modauthopenidc incorrectly handled certain POST requests. An attacker could possibly use this issue to obtain sensitive information.
{ "binaries": [ { "binary_name": "libapache2-mod-auth-openidc", "binary_version": "2.4.11-1ubuntu0.1" } ], "availability": "No subscription required" }
{ "ecosystem": "Ubuntu:22.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-31492" } ] }
{ "binaries": [ { "binary_name": "libapache2-mod-auth-openidc", "binary_version": "2.4.15.1-1ubuntu0.1" } ], "availability": "No subscription required" }
{ "ecosystem": "Ubuntu:24.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-31492" } ] }
{ "binaries": [ { "binary_name": "libapache2-mod-auth-openidc", "binary_version": "2.4.16.10-1ubuntu1" } ], "availability": "No subscription required" }
{ "ecosystem": "Ubuntu:25.04", "cves": [ { "severity": [ { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-31492" } ] }