PT-2019-5693 · Apache+3 · Mod Auth Mellon+4

Publicado

2019-06-20

·

Atualizado

2023-03-13

·

CVE-2019-13038

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions mod auth mellon versions 0.14.2 and earlier
Description The issue is related to an Open Redirect via the login?ReturnTo= substring. This can be exploited by omitting the // after http: in the target URL, allowing a remote attacker to redirect users to a malicious site using the ReturnTo= parameter. The vulnerability is associated with the apr uri parse() function in the mod auth mellon authentication module for Apache HTTP Server.
Recommendations For mod auth mellon versions 0.14.2 and earlier, consider disabling the login functionality until a patch is available. Restrict access to the login?ReturnTo= endpoint to minimize the risk of exploitation. Avoid using the ReturnTo parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-05766
CESA-2020_1003
CESA-2020_1660
CVE-2019-13038
DLA-3359-1
RHSA-2020:1003
RHSA-2020:1660
RHSA-2020_1003
RHSA-2020_1660
USN-4291-1

Produtos afetados

Apache Http Server
Centos
Red Hat
Ubuntu
Mod Auth Mellon