Your message dated Sat, 18 Feb 2023 19:02:26 +0000
with message-id <[email protected]>
and subject line Bug#1026444: fixed in libapache2-mod-auth-openidc 
2.4.9.4-0+deb11u2
has caused the Debian Bug report #1026444,
regarding libapache2-mod-auth-openidc: CVE-2022-23527
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1026444: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026444
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libapache2-mod-auth-openidc
Severity: important
Tags: patch upstream security
X-Debbugs-Cc: Debian Security Team <[email protected]>

Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a
logout parameter to the redirect URI, the existing code in
oidc_validate_redirect_url() does not properly check for URLs that start with
/\t, leading to an open redirect. This issue has been patched in version
2.4.12.2. Users unable to upgrade can mitigate the issue by configuring
mod_auth_openidc to only allow redirection when the destination matches a given
regular expression with OIDCRedirectURLsAllowed.

https://security-tracker.debian.org/tracker/CVE-2022-23527

https://github.com/zmartzone/mod_auth_openidc/security/advisories/GHSA-q6f2-285m-gr53

https://github.com/zmartzone/mod_auth_openidc/commit/87119f44b9a88312dbc1f752d720bcd2371b94a8


-- System Information:
Debian Release: bookworm/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 6.0.0-5-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

--- End Message ---
--- Begin Message ---
Source: libapache2-mod-auth-openidc
Source-Version: 2.4.9.4-0+deb11u2
Done: Moritz Schlarb <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libapache2-mod-auth-openidc, which is due to be installed in the Debian FTP 
archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Schlarb <[email protected]> (supplier of updated 
libapache2-mod-auth-openidc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 20 Dec 2022 12:20:52 +0100
Source: libapache2-mod-auth-openidc
Architecture: source
Version: 2.4.9.4-0+deb11u2
Distribution: bullseye
Urgency: medium
Maintainer: Moritz Schlarb <[email protected]>
Changed-By: Moritz Schlarb <[email protected]>
Closes: 1026444
Changes:
 libapache2-mod-auth-openidc (2.4.9.4-0+deb11u2) bullseye; urgency=medium
 .
   * Backport fix for CVE-2022-23527: prevent open redirect in default setup
     when OIDCRedirectURLsAllowed is not configured
     see: 
https://github.com/zmartzone/mod_auth_openidc/security/advisories/GHSA-q6f2-285m-gr53
     (Closes: #1026444)
Checksums-Sha1:
 5d8caa209a21c777bb88a99bbd8f83e7153a682b 2560 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2.dsc
 722f61be486e52e9a28f2e8808b541b68e3615eb 6992 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2.debian.tar.xz
 ceb63ca3fb70c46a2a6fa2551c7b7d8510ffc783 8599 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2_amd64.buildinfo
Checksums-Sha256:
 760e1cfa5fd4e8346941ecb6d42db66ed7daa761b3b2e5937de1ca4a51b290e9 2560 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2.dsc
 4a82333b90029003f18fe41f3be921157d0116efa1c413abb698d08b80243c85 6992 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2.debian.tar.xz
 ac05fd8680059bce33ae87c01affe828a0181d8c3e401fe708701dc580311ff1 8599 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2_amd64.buildinfo
Files:
 6dcdf43c0903512c0ba7a4202ea9c24f 2560 httpd optional 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2.dsc
 60a2f18302b7988163a8baf090d324a1 6992 httpd optional 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2.debian.tar.xz
 e9e4667a8fcb9e59da554fcb3c4c426e 8599 httpd optional 
libapache2-mod-auth-openidc_2.4.9.4-0+deb11u2_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJKBAEBCgA0FiEE3wEiR7/GVQGv8oRFDCS4Qcfduq8FAmOhqVYWHHNjaGxhcmJt
QHVuaS1tYWluei5kZQAKCRAMJLhBx926r4+8D/9tkLxn3jmUI5LavWzzJShn5LuG
6kFHwSubiF3n/Ll//XlvO6bjbPKkrB6V3s8hhcooipPjxQbfKxttkaCz83c86jl4
zrxrAaPrnoGkDfDlpIYCqVqs3Oz+2wr0tOTuqRtwNdTw91m2payJcEcr2QX2U8+p
Vxx7Kfr8soFsF3cpMQUB6tKTm2AYXzNlK4ZTpfxBbiPxw7zDZeTVqJhHNkL+tcRL
Dm8d/5JBKd8XbKy9IkvXz/TsaOQl+goVk6goqr00WOorerYHKJIoDBwas+wV1yEx
FG+Ydw3XUWlPDANV0PmuPMyrVFealpoVx7++A5gG7FKR3vrj+3YWGPj7Fx3oPDYr
nFT4sbcfYQX4YeiOEZ9XRcFjnbQ6GR6Fb/ZySB/jWUUnFY+AlFBhit2oPw3OQf5E
4awPpo3qSVdhoXKw+01u7NQeYUvvPmrHPNWtLFZDEY0YIAqhEM89ZRrlet2lzbdP
FG1umXcybLEe9McC1O7a4qdYw7U5QNi4zFRSq39bkPxzY778uphSzK3udSIyW0di
fxpDJ8Gbz2rcDU9busHYTXGpaQjVMYBeOIZK+om9NN5je4iL++WjbY66r7DlTTwg
27hjWiEhiqXD9rsm2RV9KtwLlyJX7OMjYakuVZDBltakT1BX728FrCp9Qf/Wcy+6
R+OqWhiO7TrJuEsa7w==
=QSBQ
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to