Red Hat Security Advisory: mod_auth_openidc:2.3 security update
A denial of service (DoS) vulnerability exists in the mod_auth_openidc Apache HTTP Server module when using the OIDCSessionType client-cookie configuration and manipulating cookies. This vulnerability is identified as CVE-2024-24814 and has been rated with moderate security impact by Red Hat. The issue affects Red Hat Enterprise Linux 8 versions of mod_auth_openidc. Red Hat has released an update to address this vulnerability.
AI Analysis
Technical Summary
CVE-2024-24814 is a denial of service vulnerability in the mod_auth_openidc module for Apache HTTP Server, which enables OpenID Connect and OAuth 2.0 authentication. The flaw occurs when the module is configured with OIDCSessionType set to client-cookie and an attacker manipulates cookies, potentially causing a denial of service. Red Hat has issued a security advisory (RHSA-2024:5289) providing an updated version of mod_auth_openidc to fix this issue. The advisory covers Red Hat Enterprise Linux 8 across multiple architectures.
Potential Impact
Successful exploitation of this vulnerability can cause a denial of service condition in the Apache HTTP Server using mod_auth_openidc with client-cookie session type. This may disrupt authentication services relying on this module, impacting availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released an updated version of mod_auth_openidc as part of Red Hat Enterprise Linux 8 updates to address this vulnerability. Users should apply the official Red Hat update as described in advisory RHSA-2024:5289 and the referenced article https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor.
Red Hat Security Advisory: mod_auth_openidc:2.3 security update
Description
A denial of service (DoS) vulnerability exists in the mod_auth_openidc Apache HTTP Server module when using the OIDCSessionType client-cookie configuration and manipulating cookies. This vulnerability is identified as CVE-2024-24814 and has been rated with moderate security impact by Red Hat. The issue affects Red Hat Enterprise Linux 8 versions of mod_auth_openidc. Red Hat has released an update to address this vulnerability.
Affected software
pkg:rpm/redhat/mod_auth_openidcRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-24814 is a denial of service vulnerability in the mod_auth_openidc module for Apache HTTP Server, which enables OpenID Connect and OAuth 2.0 authentication. The flaw occurs when the module is configured with OIDCSessionType set to client-cookie and an attacker manipulates cookies, potentially causing a denial of service. Red Hat has issued a security advisory (RHSA-2024:5289) providing an updated version of mod_auth_openidc to fix this issue. The advisory covers Red Hat Enterprise Linux 8 across multiple architectures.
Potential Impact
Successful exploitation of this vulnerability can cause a denial of service condition in the Apache HTTP Server using mod_auth_openidc with client-cookie session type. This may disrupt authentication services relying on this module, impacting availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released an updated version of mod_auth_openidc as part of Red Hat Enterprise Linux 8 updates to address this vulnerability. Users should apply the official Red Hat update as described in advisory RHSA-2024:5289 and the referenced article https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:5289
- Cve Count
- 1
Threat ID: 6a7c9b57bf8831d539cde613
Added to database: 08/12/2026, 16:12:07 UTC
Last enriched: 08/12/2026, 17:09:03 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.