cbcvebase.

Debian Libapache2-Mod-Auth-Mellon vulnerabilities

9 known vulnerabilities affecting debian/libapache2-mod-auth-mellon.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2019-3878P3HIGHCVSS 8.1fixed in libapache2-mod-auth-mellon 0.14.2-1 (bookworm)2019
CVE-2019-3878 [HIGH] CVE-2019-3878: libapache2-mod-auth-mellon - A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is config... A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentic
debian
CVE-2014-8567P3CRITICALCVSS 9.4fixed in libapache2-mod-auth-mellon 0.9.0 (bookworm)2014
CVE-2014-8567 [CRITICAL] CVE-2014-8567: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denia... The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data. Scope: local bookworm: resolved (fixed in 0.9.0) bullseye: resolved (fixed in 0.9.0) forky: resolved (fixed in 0.9.0) sid: resolved (fixed in 0.9.0) trixi
debian
CVE-2016-2146P3HIGHCVSS 7.5fixed in libapache2-mod-auth-mellon 0.12.0-1 (bookworm)2016
CVE-2016-2146 [HIGH] CVE-2016-2146: libapache2-mod-auth-mellon - The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit t... The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data. Scope: local bookworm: resolved (fixed in 0.12.0-1) bullseye: resolved (fixed in 0.12.0-
debian
CVE-2016-2145P3HIGHCVSS 7.5fixed in libapache2-mod-auth-mellon 0.12.0-1 (bookworm)2016
CVE-2016-2145 [HIGH] CVE-2016-2145: libapache2-mod-auth-mellon - The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check i... The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data. Scope: local bookworm: resolved (fixed in 0.12.0-1) bullseye: resolved (fixed in 0.12.0-1) fork
debian
CVE-2019-3877P4MEDIUMCVSS 5.8fixed in libapache2-mod-auth-mellon 0.14.2-1 (bookworm)2019
CVE-2019-3877 [MEDIUM] CVE-2019-3877: libapache2-mod-auth-mellon - A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in... A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redire
debian
CVE-2021-3639P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-mellon 0.18.0-1 (bookworm)2021
CVE-2021-3639 [MEDIUM] CVE-2021-3639: libapache2-mod-auth-mellon - A flaw was found in mod_auth_mellon where it does not sanitize logout URLs prope... A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and in
debian
CVE-2014-8566P4MEDIUMCVSS 6.4fixed in libapache2-mod-auth-mellon 0.9.1 (bookworm)2014
CVE-2014-8566 [MEDIUM] CVE-2014-8566: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensit... The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory." Scope: local bookworm: resolved (fixed in 0.9.1) bullseye: resolved (fixed in 0.9.1) forky: resolved (f
debian
CVE-2017-6807P4MEDIUMCVSS 6.1fixed in libapache2-mod-auth-mellon 0.12.0-2 (bookworm)2017
CVE-2017-6807 [MEDIUM] CVE-2017-6807: libapache2-mod-auth-mellon - mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer att... mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site. Scope: local bookworm: resolved (fixed in 0.12.0-2) bullseye: resolved (fixed in 0.12.0-2) forky: reso
debian
CVE-2019-13038P4LOWCVSS 6.1fixed in libapache2-mod-auth-mellon 0.15.0-1 (bookworm)2019
CVE-2019-13038 [MEDIUM] CVE-2019-13038: libapache2-mod-auth-mellon - mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= subs... mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. Scope: local bookworm: resolved (fixed in 0.15.0-1) bullseye: resolved (fixed in 0.15.0-1) forky: resolved (fixed in 0.15.0-1) sid: resolved (fixed in 0.15.0-1) trixie: resolved (fixed in 0.15.0
debian
Debian Libapache2-Mod-Auth-Mellon vulnerabilities | cvebase