CVE-2019-3877
Last modified
CVE-2019-3877 is a vulnerability of currently unknown severity. A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mod Auth Mellon Project | Mod Auth Mellon | < 0.14.2 |
| Fedoraproject | Fedora | 29 |
| Redhat | Enterprise Linux | 7.0 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3877Issue Tracking, Patch, Third Party Advisory
- https://github.com/Uninett/mod_auth_mellon/commit/62041428a32de402e0be6ba45fe12df6a83bedb8Patch, Third Party Advisory
- https://github.com/Uninett/mod_auth_mellon/issues/35Patch, Third Party Advisory
- https://usn.ubuntu.com/3924-1/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3877Issue Tracking, Patch, Third Party Advisory
- https://github.com/Uninett/mod_auth_mellon/commit/62041428a32de402e0be6ba45fe12df6a83bedb8Patch, Third Party Advisory
- https://github.com/Uninett/mod_auth_mellon/issues/35Patch, Third Party Advisory
- https://usn.ubuntu.com/3924-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3877?
How severe is CVE-2019-3877?
How do I fix CVE-2019-3877?
Are you affected by CVE-2019-3877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
