A flaw was found in modauthopenidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
[
{
"deprecated": false,
"source": "https://github.com/openidc/mod_auth_openidc/commit/94d2cf2bd4581b0c393b750587b621d33e2f4e0e",
"id": "CVE-2019-20479-05aa1e3f",
"target": {
"file": "src/cache/common.c",
"function": "oidc_cache_mutex_destroy"
},
"digest": {
"function_hash": "292571528579285139739553888024721725778",
"length": 553.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/openidc/mod_auth_openidc/commit/94d2cf2bd4581b0c393b750587b621d33e2f4e0e",
"id": "CVE-2019-20479-339a2278",
"target": {
"file": "src/cache/common.c"
},
"digest": {
"line_hashes": [
"199370385196264008088677233345752309063",
"5074136558242366934413352575790907147",
"65396395535408745366843203444097860275",
"115734331422631327239312339581567078434",
"244197310894902504449748704406048077242",
"279679966921650120632441670303460601414",
"50353192814854080748463185925216379361",
"288313765875823845552638405548810835708",
"329082806999490161391590921094917349001",
"112785618798974126610844099124471876307",
"183711922263090499335521941596037306329",
"116984925139315876825063513942341048620",
"43917158376661601226679076315876029190",
"329770745295793924214238739214481751620",
"119531293556308819516382198959556804849",
"126490398248283259180254736651881614186",
"321801973304148796263225390607756681945",
"259434629331703982302890190343030298605"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/openidc/mod_auth_openidc/commit/94d2cf2bd4581b0c393b750587b621d33e2f4e0e",
"id": "CVE-2019-20479-7bed0376",
"target": {
"file": "src/cache/shm.c"
},
"digest": {
"line_hashes": [
"9786757787665961887895905625459747500",
"124355243522583329622942131911663822078",
"53210297840531005206572427125477654461",
"122317155771460493737853805728013356384",
"151341049909999925075959818082636278347",
"115864870007998282574785941438617754608",
"80445514014107175002522979962412074664"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/openidc/mod_auth_openidc/commit/94d2cf2bd4581b0c393b750587b621d33e2f4e0e",
"id": "CVE-2019-20479-a7ec0fae",
"target": {
"file": "src/cache/shm.c",
"function": "oidc_cache_shm_destroy"
},
"digest": {
"function_hash": "21434340826836178884602067701743101447",
"length": 496.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/openidc/mod_auth_openidc/commit/94d2cf2bd4581b0c393b750587b621d33e2f4e0e",
"id": "CVE-2019-20479-bf29c084",
"target": {
"file": "src/cache/common.c",
"function": "oidc_cache_mutex_post_config"
},
"digest": {
"function_hash": "208742624046330703456231157834671144335",
"length": 1286.0
},
"signature_type": "Function",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20479.json"