mod_auth_mellon_project CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

mod_auth_mellon_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all mod_auth_mellon_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk open redirect and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-13038 mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. [email protected] 6.1 0.59% 2019-06-29 2024-11-21
CVE-2019-3877 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function. [email protected] 5.8 0.81% 2019-03-27 2024-11-21
CVE-2019-3878 A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication. [email protected] 8.1 2.01% 2019-03-26 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence