Mod Auth Mellon Project Mod Auth Mellon vulnerabilities
3 known vulnerabilities affecting mod_auth_mellon_project/mod_auth_mellon.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-13038MEDIUMCVSS 6.1≤ 0.14.22019-06-29
CVE-2019-13038 [MEDIUM] CWE-601 CVE-2019-13038: mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrat
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
nvd
CVE-2019-3877MEDIUMCVSS 6.1fixed in 0.14.22019-03-27
CVE-2019-3877 [MEDIUM] CWE-601 CVE-2019-3877: A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allo
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect U
nvd
CVE-2019-3878HIGHCVSS 8.1fixed in 0.14.22019-03-26
CVE-2019-3878 [HIGH] CWE-305 CVE-2019-3878: A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse pr
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authenticatio
nvd