mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
CVSS Details
- CVSS 3.0 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade mod24_auth_mellonUpgrade mod_auth_mellon | Mar 9, 2018 | Mar 13, 2017 |
| Debian | — | Upgrade libapache2-mod-auth-mellon | Jul 30, 2024 | Mar 13, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade mod_auth_mellon | Dec 4, 2019 | Mar 13, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mod_auth_mellon | Dec 18, 2019 | Mar 13, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 13, 2017 |
| Ubuntu | — | Upgrade libapache2-mod-auth-mellon | Oct 23, 2020 | Mar 13, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub