Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-6059 Details

Description

Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2019:2112 CVEThird Party Advisory
https://github.com/pingidentity/mod_auth_openidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4 CVEPatchThird Party Advisory
https://github.com/pingidentity/mod_auth_openidc/issues/212 CVEIssue TrackingPatchThird Party Advisory
https://github.com/pingidentity/mod_auth_openidc/releases/tag/v2.1.4 CVEPatchRelease NotesThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2V3HIGXMUKJGOBMAQAQPGC7G5YYWSUVA/ CVE

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
openidc mod auth openidc
< 2.1.4

CPE

  • cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-6059
NVD Published Date:
Apr 12, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-6059 Details - Not Deferred