CVE-2019-3877Open Redirect in Auth Mellon Project MOD Auth Mellon

CWE-601Open Redirect14 documents8 sources
Severity
6.1MEDIUMNVD
CNA5.8
EPSS
0.8%
top 25.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 14

Description

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Also affects: Fedora 29, Ubuntu Linux 18.04, 18.10, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-qr9h-f4fq-2h85: A vulnerability was found in mod_auth_mellon before v02022-05-14
OSV
libapache2-mod-auth-mellon vulnerabilities2020-10-22
OSV
libapache2-mod-auth-mellon vulnerabilities2019-03-28
CVEList
CVE-2019-3877: A vulnerability was found in mod_auth_mellon before v02019-03-27
OSV
CVE-2019-3877: A vulnerability was found in mod_auth_mellon before v02019-03-27

📋Vendor Advisories

5
Ubuntu
mod_auth_mellon vulnerabilities2020-10-22
Red Hat
mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes2019-10-02
Ubuntu
mod_auth_mellon vulnerabilities2019-03-28
Red Hat
mod_auth_mellon: open redirect in logout url when using URLs with backslashes2019-03-22
Debian
CVE-2019-3877: libapache2-mod-auth-mellon - A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in...2019

💬Community

3
Bugzilla
CVE-2019-14857 mod_auth_openidc: Open redirect in logout url when using URLs with leading slashes2019-10-10
Bugzilla
CVE-2019-3877 mod_auth_mellon: open redirect in logout url when using URLs with backslashes [fedora-all]2019-03-22
Bugzilla
CVE-2019-3877 mod_auth_mellon: open redirect in logout url when using URLs with backslashes2019-03-20
CVE-2019-3877 — Open Redirect | cvebase