CVE-2021-3639 — Open Redirect in MOD Auth Mellon
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 58.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateAug 23
Description
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-mhcv-7w89-jjj5: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly↗2022-08-23
CVEList▶
CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly↗2022-08-22
OSV▶
CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly↗2022-08-22
📋Vendor Advisories
5Microsoft▶
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted we↗2022-08-09
Debian▶
CVE-2021-3639: libapache2-mod-auth-mellon - A flaw was found in mod_auth_mellon where it does not sanitize logout URLs prope...↗2021