The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka modauthopenidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDCCLAIM and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.
{
"cpe": "cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.1.5"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-08T12:05:26Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"252592132319974117317083050032030932584",
"245854842247398335139041577994342478702",
"249301519142228043284928015001881791252",
"12496067092907532332299473183032362101"
]
},
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e",
"id": "CVE-2017-6413-15b46186",
"target": {
"file": "src/mod_auth_openidc.h"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 395.0,
"function_hash": "235345058986512073726030606729054536041"
},
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e",
"id": "CVE-2017-6413-9eab6cc5",
"target": {
"function": "oidc_scrub_headers",
"file": "src/mod_auth_openidc.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2113.0,
"function_hash": "101436493843902703457223292790871171117"
},
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e",
"id": "CVE-2017-6413-b96c5034",
"target": {
"function": "oidc_oauth_check_userid",
"file": "src/oauth.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"300885929279668652631216083908378489803",
"86757556201774335385049608529931441491",
"232568871630841356922068682392364302614"
]
},
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e",
"id": "CVE-2017-6413-bc595be3",
"target": {
"file": "src/oauth.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"231156241331446138400413118183185546010",
"328211974302038262523992695704363018362",
"75708323700389784035179034936157320920",
"339048421168395487366516423266575270949"
]
},
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e",
"id": "CVE-2017-6413-efae51a6",
"target": {
"file": "src/mod_auth_openidc.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6413.json"