The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
{
"cpe": "cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.1.4"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6062.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"324389110975062152997128778931728905211",
"152318813777326227190711828689954873884",
"121968274078813223348073188492985639520",
"195878975772069471775001186274537783816",
"14068290540346082033104791455712297064",
"110055679037368288760605636742227139861",
"111294165517741646199017371710611676395",
"278945173429800584441645734551228449926",
"142421153620309442185703083496499538401",
"236743154285405913172971894557261355266",
"143690780221429256596881591379080579095",
"83774172051446986695428302243052929936",
"117984124392778747583104912066583298362",
"173927667228971011105139773653306542747",
"286862810251338442830903801741102728729",
"130566670204652639318084985979800826271",
"329389427395940680308013088225565378365",
"145764464254468082961938229952210584802"
],
"threshold": 0.9
},
"id": "CVE-2017-6062-52ab9169",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/e81822a7d5f5bdf04ba03ca92680821893303850",
"target": {
"file": "src/mod_auth_openidc.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "23087062502499850250068183479776194754",
"length": 1680
},
"id": "CVE-2017-6062-77543a8e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/e81822a7d5f5bdf04ba03ca92680821893303850",
"target": {
"file": "src/mod_auth_openidc.c",
"function": "oidc_check_userid_openidc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "301378486185075427509235490601443248735",
"length": 2785
},
"id": "CVE-2017-6062-c9ad601c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/e81822a7d5f5bdf04ba03ca92680821893303850",
"target": {
"file": "src/mod_auth_openidc.c",
"function": "oidc_handle_existing_session"
}
}
]
"2026-07-08T12:28:04Z"