PT-2019-5693 · Apache+3 · Mod Auth Mellon+4
Published
2019-06-20
·
Updated
2023-03-13
·
CVE-2019-13038
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
mod auth mellon versions 0.14.2 and earlier
Description
The issue is related to an Open Redirect via the
login?ReturnTo= substring. This can be exploited by omitting the // after http: in the target URL, allowing a remote attacker to redirect users to a malicious site using the ReturnTo= parameter. The vulnerability is associated with the apr uri parse() function in the mod auth mellon authentication module for Apache HTTP Server.Recommendations
For mod auth mellon versions 0.14.2 and earlier, consider disabling the login functionality until a patch is available. Restrict access to the
login?ReturnTo= endpoint to minimize the risk of exploitation. Avoid using the ReturnTo parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Centos
Red Hat
Ubuntu
Mod Auth Mellon