CVE-2012-2760: Findingscience Mod Auth Openid
Low severity, CVSS 2.1. EPSS: 1% chance of exploitation in the next 30 days.
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
Affected products
- Findingscience Mod Auth Openid: up to and including 0.6; version 0.1 only; version 0.2 only; version 0.2.1 only; version 0.3 only; version 0.4 only; …
Published 2012-07-25. Last modified 2026-06-16.