cbcvebase.
CVE-2019-3878
published 2019-03-26

CVE-2019-3878: A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through…

high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlibapache2-mod-auth-mellon< libapache2-mod-auth-mellon 0.14.2-1 (bookworm)libapache2-mod-auth-mellon 0.14.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
mod_auth_mellon_projectmod_auth_mellon< 0.14.20.14.2
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
uninettmod_auth_mellon

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH