CVE-2012-2760: Findingscience Mod Auth Openid

Low severity, CVSS 2.1. EPSS: 1% chance of exploitation in the next 30 days.

mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.

Affected products

  • Findingscience Mod Auth Openid: up to and including 0.6; version 0.1 only; version 0.2 only; version 0.2.1 only; version 0.3 only; version 0.4 only; …

Published 2012-07-25. Last modified 2026-06-16.