Commit Graph

5 Commits

Author SHA1 Message Date
Tomas Halman
44608630dc Rebase to 2.4.10 version
Improves: `state cookies piling up` problem

Resolves: RHEL-32450 Race condition in mod_auth_openidc filecache
Resolves: RHEL-25422 mod_auth_openidc: DoS when using
          `OIDCSessionType client-cookie` and manipulating cookies
          (CVE-2024-24814)
2024-05-15 13:19:39 +02:00
Tomas Halman
b2f5928aaf Rebase to 2.4.9.4
Resolves: rhbz#2001852 CVE-2021-39191 mod_auth_openidc: open redirect
                       by supplying a crafted URL in the target_link_uri
                       parameter
2021-11-30 11:17:56 +01:00
Jakub Hrozek
bb118db4de Rebase to 2.4.9
Resolves: rhbz#1987223 - CVE-2021-32792 mod_auth_openidc: XSS when using
                           OIDCPreservePost On [rhel-9.0]
Resolves: rhbz#1987217 - CVE-2021-32791 mod_auth_openidc: hardcoded
                           static IV and AAD with a reused key in AES GCM
                           encryption [rhel-9.0]
Resolves: rhbz#1987204 - CVE-2021-32786 mod_auth_openidc: open redirect in
                           oidc_validate_redirect_url() [rhel-9.0]
2021-08-18 13:53:34 +02:00
Jakub Hrozek
2b73a00d38 New upstream release
mod_auth_openidc-2.4.8.2 is available
Resolves: rhbz#1961213
2021-05-17 17:09:30 +02:00
Petr Šabata
66a7041a6e RHEL 9.0.0 Alpha bootstrap
The content of this branch was automatically imported from Fedora ELN
with the following as its source:
https://src.fedoraproject.org/rpms/mod_auth_openidc#5f2d016252774bc0efe44f7de9ea1366142f3f9c
2020-10-15 19:52:44 +02:00