CVE-2019-20479
Alma Linux vulnerability analysis and mitigation

Overview

A security vulnerability (CVE-2019-20479) was discovered in mod_auth_openidc before version 2.4.1. The vulnerability is characterized by an open redirect issue that exists in URLs with a slash and backslash at the beginning. This flaw affects the OpenID Connect authentication module for Apache HTTP Server, which enables Apache to operate as an OpenID Connect Relying Party and OAuth 2.0 Resource Server (NVD, Debian Tracker).

Technical details

The vulnerability stems from insufficient validation of URLs that begin with a slash and backslash combination (/). When processing such URLs, the module fails to properly validate the redirect destination, potentially allowing malicious redirects. The issue was discovered and reported in late 2019, with a CVSS v3 score of 6.1 indicating moderate severity (Red Hat Portal).

Impact

The vulnerability could allow an attacker to perform open redirect attacks. When exploited, an attacker could redirect users to malicious websites, potentially leading to phishing attacks or other malicious activities. This is particularly concerning in the context of authentication systems where users might be tricked into providing credentials to illegitimate websites (Debian LTS).

Mitigation and workarounds

The vulnerability was fixed in mod_auth_openidc version 2.4.1 and later releases. Organizations are strongly recommended to upgrade to the patched version. Various distributions have released security updates to address this vulnerability, including Debian, Fedora, and Red Hat Enterprise Linux (Fedora Update, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0891HIGH8.1
  • Mozilla FirefoxMozilla Firefox
  • MozillaFirefox
NoYesJan 13, 2026
CVE-2025-24528HIGH7.1
  • KerberosKerberos
  • krb5
NoYesJan 16, 2026
CVE-2026-0890MEDIUM5.4
  • Mozilla FirefoxMozilla Firefox
  • firefox-esr
NoYesJan 13, 2026
CVE-2026-0886MEDIUM5.3
  • Mozilla FirefoxMozilla Firefox
  • MozillaThunderbird-translations-common
NoYesJan 13, 2026
CVE-2026-0887MEDIUM4.3
  • Mozilla FirefoxMozilla Firefox
  • MozillaFirefox-branding-upstream
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management