CVE-2021-3639Open Redirect in MOD Auth Mellon

CWE-601Open Redirect9 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 58.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateAug 23

Description

A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5uninett/mod_auth_mellonFixed in v0.18.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mhcv-7w89-jjj5: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly2022-08-23
CVEList
CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly2022-08-22
OSV
CVE-2021-3639: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly2022-08-22

📋Vendor Advisories

5
Microsoft
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted we2022-08-09
Ubuntu
mod-auth-mellon vulnerability2021-09-08
Ubuntu
mod-auth-mellon vulnerability2021-09-08
Red Hat
mod_auth_mellon: Open Redirect vulnerability in logout URLs2021-07-29
Debian
CVE-2021-3639: libapache2-mod-auth-mellon - A flaw was found in mod_auth_mellon where it does not sanitize logout URLs prope...2021
CVE-2021-3639 — Open Redirect in MOD Auth Mellon | cvebase