PatchSiren cyber security CVE debrief
CVE-2017-6062 Openidc CVE debrief
CVE-2017-6062 is a high-severity authentication bypass in mod_auth_openidc for Apache HTTP Server. In affected versions before 2.1.5, the module does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers when OIDCUnAuthAction pass is configured, which can allow remote attackers to bypass authentication through crafted HTTP traffic.
- Vendor
- Openidc
- Product
- Mod Auth Openidc
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Organizations running Apache HTTP Server with mod_auth_openidc, especially deployments using OIDCUnAuthAction pass. Web platform owners, identity and access management teams, and operators responsible for reverse proxies or authenticated web apps should treat this as a priority because the issue affects authentication enforcement directly.
Technical summary
NVD records this as CVE-2017-6062 with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N and CWE-287. The vulnerable condition is limited to mod_auth_openidc versions through 2.1.4. The module fails to ignore OIDC_CLAIM_ and OIDCAuthNHeader headers in the OIDCUnAuthAction pass configuration, creating a path for remote authentication bypass.
Defensive priority
High. The issue is network-reachable, requires no privileges or user interaction, and affects authentication integrity. Systems exposing the affected configuration should be patched promptly and reviewed for compensating controls.
Recommended defensive actions
- Upgrade mod_auth_openidc to version 2.1.5 or later.
- Review Apache HTTP Server configurations that use OIDCUnAuthAction pass and validate that the affected headers are not accepted in a way that weakens authentication.
- Audit deployments for any reliance on pre-2.1.5 behavior and test authentication flows after upgrading.
- Monitor related vendor notes, changelog entries, and downstream package advisories for the exact fixed package versions in your distribution.
Evidence notes
This debrief is based on the official NVD record and the linked project references. NVD describes the affected range as versions through 2.1.4 and lists the impact as authentication bypass with CWE-287. The project changelog, issue tracker entry, and v2.1.5 release notes are the supplied vendor-linked references indicating the fix and release context. No exploit steps are included here.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6062 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6062
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6062 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6062
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/pingidentity/mod_auth_openidc/blob/master/ChangeLog
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/pingidentity/mod_auth_openidc/issues/222
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/pingidentity/mod_auth_openidc/releases/tag/v2.1.5
[email protected] - Patch, Release Notes, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2V3HIGXMUKJGOBMAQAQPGC7G5YYWSUVA/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EJXBG3DG2FUYFGTUTSJFMPIINVFKKB4Z/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTWUMQ46GZY3O4WU4JCF333LN53R2XQH/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.