CVE-2021-3639
published 2022-08-22CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.75%
50.9th percentile
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libapache2-mod-auth-mellon | < libapache2-mod-auth-mellon 0.18.0-1 (bookworm) | libapache2-mod-auth-mellon 0.18.0-1 (bookworm) |
| msrc | cbl2_mod_auth_mellon_0.16.0-4_on_cbl_mariner_2.0 | — | — |
| uninett | mod_auth_mellon | < 0.18.0 | 0.18.0 |
| uninett | mod_auth_mellon | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted we
vendor_msrc·2022-08-09·CVSS 6.1
CVE-2021-3639 [MEDIUM] CWE-601 A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted we
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is
Ubuntu
mod-auth-mellon vulnerability
vendor_ubuntu·2021-09-08
CVE-2021-3639 mod-auth-mellon vulnerability
Title: mod-auth-mellon vulnerability
Summary: mod-auth-mellon could be made to redirect to arbitrary sites.
It was discovered that mod-auth-mellon incorrectly filtered certain URLs.
A remote attacker could possibly use this issue to perform an open redirect
attack.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
mod-auth-mellon vulnerability
vendor_ubuntu·2021-09-08
CVE-2021-3639 mod-auth-mellon vulnerability
Title: mod-auth-mellon vulnerability
Summary: mod-auth-mellon could be made to redirect to arbitrary sites.
USN-5069-1 fixed a vulnerability in mod-auth-mellon. This update provides
the corresponding updates for Ubuntu 21.04.
Original advisory details:
It was discovered that mod-auth-mellon incorrectly filtered certain URLs.
A remote attacker could possibly use this issue to perform an open redirect
attack.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
mod_auth_mellon: Open Redirect vulnerability in logout URLs
vendor_redhat·2021-07-29·CVSS 6.1
CVE-2021-3639 [MEDIUM] CWE-601 mod_auth_mellon: Open Redirect vulnerability in logout URLs
mod_auth_mellon: Open Redirect vulnerability in logout URLs
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
Package: mod_auth_mel
Debian
CVE-2021-3639: libapache2-mod-auth-mellon - A flaw was found in mod_auth_mellon where it does not sanitize logout URLs prope...
vendor_debian·2021·CVSS 6.1
CVE-2021-3639 [MEDIUM] CVE-2021-3639: libapache2-mod-auth-mellon - A flaw was found in mod_auth_mellon where it does not sanitize logout URLs prope...
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 0.18.0-1)
bullseye: resolved (fixed in 0.17.0-1+deb11u1)
forky: resolved (fixed in 0.18.0-1)
sid: resolved (fixed in 0.18.0-1)
trixie: resolved (fixed in 0.18.0-1)
GHSA
GHSA-mhcv-7w89-jjj5: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly
ghsa_unreviewed·2022-08-23
CVE-2021-3639 [MEDIUM] CWE-601 GHSA-mhcv-7w89-jjj5: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
OSV
CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly
osv·2022-08-22·CVSS 6.1
CVE-2021-3639 [MEDIUM] CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3639https://bugzilla.redhat.com/show_bug.cgi?id=1980648https://github.com/latchset/mod_auth_mellon/commit/42a11261b9dad2e48d70bdff7c53dd57a12db6f5https://access.redhat.com/security/cve/CVE-2021-3639https://bugzilla.redhat.com/show_bug.cgi?id=1980648https://github.com/latchset/mod_auth_mellon/commit/42a11261b9dad2e48d70bdff7c53dd57a12db6f5
2022-08-22
Published