Impact
An unauthenticated attacker can crash the Apache httpd process by sending a POST request without a Content-Type header when OIDCPreservePost is enabled in mod_auth_openidc. This leads to denial of service.
Patches
Users should upgrade to a version of mod_auth_openidc greater than 2.4.13.1.
Workarounds
There are no workarounds other than disabling OIDCPreservePost.
References
https://bugzilla.redhat.com/show_bug.cgi?id=2361633
Impact
An unauthenticated attacker can crash the Apache httpd process by sending a POST request without a
Content-Typeheader whenOIDCPreservePostis enabled in mod_auth_openidc. This leads to denial of service.Patches
Users should upgrade to a version of mod_auth_openidc greater than 2.4.13.1.
Workarounds
There are no workarounds other than disabling
OIDCPreservePost.References
https://bugzilla.redhat.com/show_bug.cgi?id=2361633