{"id":"CVE-2017-6413","details":"The \"OpenID Connect Relying Party and OAuth 2.0 Resource Server\" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an \"AuthType oauth20\" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.","modified":"2026-07-08T12:05:26.469112Z","published":"2017-03-02T06:59:01.217Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96549"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2V3HIGXMUKJGOBMAQAQPGC7G5YYWSUVA/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EJXBG3DG2FUYFGTUTSJFMPIINVFKKB4Z/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTWUMQ46GZY3O4WU4JCF333LN53R2XQH/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2112"},{"type":"FIX","url":"https://github.com/pingidentity/mod_auth_openidc/blob/master/ChangeLog"},{"type":"FIX","url":"https://github.com/pingidentity/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e"},{"type":"FIX","url":"https://github.com/pingidentity/mod_auth_openidc/releases/tag/v2.1.6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openidc/mod_auth_openidc","events":[{"introduced":"0"},{"last_affected":"e81822a7d5f5bdf04ba03ca92680821893303850"},{"fixed":"21e3728a825c41ab41efa75e664108051bb9665e"}],"database_specific":{"cpe":"cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.1.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.1.0","v2.0.0","v2.0.0rc4","v2.0.0rc1","v1.8.10","v1.8.9","v1.8.8","v1.8.7","v1.8.6","v1.8.5","v1.8.4","v1.8.3","v1.8.2","v1.8.1","v1.8.0","v1.7.0","v1.6.0","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6413.json","vanir_signatures_modified":"2026-07-08T12:05:26Z","vanir_signatures":[{"source":"https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e","target":{"file":"src/mod_auth_openidc.h"},"deprecated":false,"digest":{"line_hashes":["252592132319974117317083050032030932584","245854842247398335139041577994342478702","249301519142228043284928015001881791252","12496067092907532332299473183032362101"],"threshold":0.9},"id":"CVE-2017-6413-15b46186","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e","target":{"file":"src/mod_auth_openidc.c","function":"oidc_scrub_headers"},"deprecated":false,"digest":{"function_hash":"235345058986512073726030606729054536041","length":395},"id":"CVE-2017-6413-9eab6cc5","signature_type":"Function","signature_version":"v1"},{"digest":{"function_hash":"101436493843902703457223292790871171117","length":2113},"id":"CVE-2017-6413-b96c5034","signature_type":"Function","signature_version":"v1","source":"https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e","target":{"function":"oidc_oauth_check_userid","file":"src/oauth.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["300885929279668652631216083908378489803","86757556201774335385049608529931441491","232568871630841356922068682392364302614"],"threshold":0.9},"id":"CVE-2017-6413-bc595be3","signature_type":"Line","signature_version":"v1","source":"https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e","target":{"file":"src/oauth.c"}},{"target":{"file":"src/mod_auth_openidc.c"},"deprecated":false,"digest":{"line_hashes":["231156241331446138400413118183185546010","328211974302038262523992695704363018362","75708323700389784035179034936157320920","339048421168395487366516423266575270949"],"threshold":0.9},"id":"CVE-2017-6413-efae51a6","signature_type":"Line","signature_version":"v1","source":"https://github.com/openidc/mod_auth_openidc/commit/21e3728a825c41ab41efa75e664108051bb9665e"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"}]}