Debian Libapache2-Mod-Auth-Mellon vulnerabilities
9 known vulnerabilities affecting debian/libapache2-mod-auth-mellon.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2019-3878P3HIGHCVSS 8.1fixed in libapache2-mod-auth-mellon 0.14.2-1 (bookworm)2019
CVE-2019-3878 [HIGH] CVE-2019-3878: libapache2-mod-auth-mellon - A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is config...
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentic
debian
CVE-2014-8567P3CRITICALCVSS 9.4fixed in libapache2-mod-auth-mellon 0.9.0 (bookworm)2014
CVE-2014-8567 [CRITICAL] CVE-2014-8567: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denia...
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
Scope: local
bookworm: resolved (fixed in 0.9.0)
bullseye: resolved (fixed in 0.9.0)
forky: resolved (fixed in 0.9.0)
sid: resolved (fixed in 0.9.0)
trixi
debian
CVE-2016-2146P3HIGHCVSS 7.5fixed in libapache2-mod-auth-mellon 0.12.0-1 (bookworm)2016
CVE-2016-2146 [HIGH] CVE-2016-2146: libapache2-mod-auth-mellon - The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit t...
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
Scope: local
bookworm: resolved (fixed in 0.12.0-1)
bullseye: resolved (fixed in 0.12.0-
debian
CVE-2016-2145P3HIGHCVSS 7.5fixed in libapache2-mod-auth-mellon 0.12.0-1 (bookworm)2016
CVE-2016-2145 [HIGH] CVE-2016-2145: libapache2-mod-auth-mellon - The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check i...
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.
Scope: local
bookworm: resolved (fixed in 0.12.0-1)
bullseye: resolved (fixed in 0.12.0-1)
fork
debian
CVE-2019-3877P4MEDIUMCVSS 5.8fixed in libapache2-mod-auth-mellon 0.14.2-1 (bookworm)2019
CVE-2019-3877 [MEDIUM] CVE-2019-3877: libapache2-mod-auth-mellon - A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in...
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redire
debian
CVE-2021-3639P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-mellon 0.18.0-1 (bookworm)2021
CVE-2021-3639 [MEDIUM] CVE-2021-3639: libapache2-mod-auth-mellon - A flaw was found in mod_auth_mellon where it does not sanitize logout URLs prope...
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and in
debian
CVE-2014-8566P4MEDIUMCVSS 6.4fixed in libapache2-mod-auth-mellon 0.9.1 (bookworm)2014
CVE-2014-8566 [MEDIUM] CVE-2014-8566: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensit...
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
Scope: local
bookworm: resolved (fixed in 0.9.1)
bullseye: resolved (fixed in 0.9.1)
forky: resolved (f
debian
CVE-2017-6807P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-mellon 0.12.0-2 (bookworm)2017
CVE-2017-6807 [MEDIUM] CVE-2017-6807: libapache2-mod-auth-mellon - mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer att...
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
Scope: local
bookworm: resolved (fixed in 0.12.0-2)
bullseye: resolved (fixed in 0.12.0-2)
forky: reso
debian
CVE-2019-13038P4LOWCVSS 6.1fixed in libapache2-mod-auth-mellon 0.15.0-1 (bookworm)2019
CVE-2019-13038 [MEDIUM] CVE-2019-13038: libapache2-mod-auth-mellon - mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= subs...
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
Scope: local
bookworm: resolved (fixed in 0.15.0-1)
bullseye: resolved (fixed in 0.15.0-1)
forky: resolved (fixed in 0.15.0-1)
sid: resolved (fixed in 0.15.0-1)
trixie: resolved (fixed in 0.15.0
debian