{"id":"CVE-2017-6059","details":"Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.","modified":"2026-07-08T16:53:08.195179Z","published":"2017-04-12T20:59:00.763Z","references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2V3HIGXMUKJGOBMAQAQPGC7G5YYWSUVA/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EJXBG3DG2FUYFGTUTSJFMPIINVFKKB4Z/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTWUMQ46GZY3O4WU4JCF333LN53R2XQH/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/02/17/6"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96299"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2112"},{"type":"FIX","url":"https://github.com/pingidentity/mod_auth_openidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4"},{"type":"FIX","url":"https://github.com/pingidentity/mod_auth_openidc/issues/212"},{"type":"FIX","url":"https://github.com/pingidentity/mod_auth_openidc/releases/tag/v2.1.4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openidc/mod_auth_openidc","events":[{"introduced":"0"},{"fixed":"66a873398aaa816460f00c3fa167315cf22436e0"},{"fixed":"612e309bfffd6f9b8ad7cdccda3019fc0865f3b4"}],"database_specific":{"cpe":"cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.1.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.1.3","v2.1.2","v2.1.1","v2.1.0","v2.0.0","v2.0.0rc4","v2.0.0rc1","v1.8.10","v1.8.9","v1.8.8","v1.8.7","v1.8.6","v1.8.5","v1.8.4","v1.8.3","v1.8.2","v1.8.1","v1.8.0","v1.7.0","v1.6.0","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6059.json","vanir_signatures_modified":"2026-07-08T16:53:08Z","vanir_signatures":[{"digest":{"line_hashes":["306393992651303049853274057305531253608","68826803240769547957311796036583225073","40663355824098006708642299200300097584","329732056193372188979464841177885681036","147759852546333290177267246415284115126"],"threshold":0.9},"id":"CVE-2017-6059-2ed07565","signature_type":"Line","signature_version":"v1","source":"https://github.com/openidc/mod_auth_openidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4","target":{"file":"src/mod_auth_openidc.c"},"deprecated":false},{"source":"https://github.com/openidc/mod_auth_openidc/commit/612e309bfffd6f9b8ad7cdccda3019fc0865f3b4","target":{"file":"src/mod_auth_openidc.c","function":"oidc_handle_redirect_uri_request"},"deprecated":false,"digest":{"function_hash":"88358408798668581522977178368894674818","length":1261},"id":"CVE-2017-6059-7f1240e7","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}