Our security team alerted me to a recently announced vulnerability in mod_auth_openidc:
- OIDCProviderAuthRequestMethod POST leaks protected data · Advisory · OpenIDC/mod_auth_openidc · GitHub
- https://access.redhat.com/errata/RHSA-2025:4128
We have some RHEL 8 systems running OOD. While Red Hat has released updated packages to fix this issue, I see a higher version of mod_auth_openidc hosted in the OOD repo which was last updated in 2023. Could you tell me:
- if you are planning on backporting this fix?
- or, is there some significant difference in functionality that would prevent me from blacklisting the package in OOD repo (2.4.14.1) and using the latest RHEL 8 release (2.4.9.4)?
Thanks,
Yan