From 286bad58f05d860c86ef6934001efcbc7d28e396 Mon Sep 17 00:00:00 2001 From: Tomas Halman Date: Tue, 25 Apr 2023 12:04:08 +0200 Subject: [PATCH] The access mode and ownership of auth_openidc.conf Resolves: rhbz#2141850 - auth_openidc.conf mode 0640 by default rhbz#2072469 - Random memory overwrite rhbz#2153659 - CVE-2022-23527 Open Redirect in oidc_validate_redirect_url() using tab character rhbz#2184144 - CVE-2023-28625 NULL pointer dereference when OIDCStripCookies is set and a crafted Cookie header is supplied