Beveiligingsadvies

CVE-2025-3891

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-29 11:56:50
Laatst bijgewerkt 2026-06-29 20:42:40
Toegewezen door redhat
CVSS-score 7.5
Status PUBLISHED

Beschrijving

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.