PT-2019-5693 · Apache+3 · Mod Auth Mellon+4
Publicado
2019-06-20
·
Atualizado
2023-03-13
·
CVE-2019-13038
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
mod auth mellon versions 0.14.2 and earlier
Description
The issue is related to an Open Redirect via the
login?ReturnTo= substring. This can be exploited by omitting the // after http: in the target URL, allowing a remote attacker to redirect users to a malicious site using the ReturnTo= parameter. The vulnerability is associated with the apr uri parse() function in the mod auth mellon authentication module for Apache HTTP Server.Recommendations
For mod auth mellon versions 0.14.2 and earlier, consider disabling the login functionality until a patch is available. Restrict access to the
login?ReturnTo= endpoint to minimize the risk of exploitation. Avoid using the ReturnTo parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Http Server
Centos
Red Hat
Ubuntu
Mod Auth Mellon