CVE-2019-14857: Openidc Mod Auth Openidc

Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.

A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.

Affected products

  • Openidc Mod Auth Openidc: before 2.4.0.1 (fixed in 2.4.0.1)

Published 2019-11-26. Last modified 2026-06-17.