Skip to content

Conversation

@jonasbardino
Copy link
Contributor

Point mod_auth_openidc to latest release if upgrade is requested with UPGRADE_MOD_AUTH_OPENIDC, in order to address a potential security issue (CVE-2025-31492) as described in the associated release notes at https://github.com/OpenIDC/mod_auth_openidc/releases/tag/v2.4.16.11

It does NOT sound like we are affected, since we don't adjust the mentioned OIDCProviderAuthRequestMethod setting in docker-migrid or migrid. Still, it may make sense to have the option to easily upgrade with the security fix and other recent bug fixes included.

NOTE: we cannot generally upgrade on CentOS 7 as well, since upstream no longer provides the corresponding packages there without a commercial support contract.

`UPGRADE_MOD_AUTH_OPENIDC`, in order to address a potential security issue
(CVE-2025-31492) as described in the associated release notes at
https://github.com/OpenIDC/mod_auth_openidc/releases/tag/v2.4.16.11

It does NOT sound like we are affected, since we don't adjust the mentioned
`OIDCProviderAuthRequestMethod` setting in docker-migrid or migrid. Still, it
may make sense to have the option to easily upgrade with the security fix and
other recent bug fixes included.
@jonasbardino jonasbardino added the bug Something isn't working label Apr 7, 2025
@jonasbardino jonasbardino added this to the Rocky9 Deployments milestone Apr 7, 2025
@jonasbardino jonasbardino requested a review from a team April 7, 2025 09:23
@jonasbardino jonasbardino self-assigned this Apr 7, 2025
Copy link
Contributor

@Martin-Rehr Martin-Rehr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@jonasbardino jonasbardino merged commit 70b005c into master Apr 7, 2025
5 checks passed
@jonasbardino jonasbardino deleted the fix/openidc-upgrade-to-address-potential-security-issue branch April 7, 2025 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants