mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mod_auth_mellon-diagnosticsUpgrade mod_auth_mellon | May 4, 2022 | Jun 29, 2019 |
| Amazon Linux Ami 2 | — | Upgrade mod_auth_mellonUpgrade mod_auth_mellon-diagnosticsUpgrade mod_auth_mellon-debuginfo | Jun 18, 2020 | Jun 29, 2019 |
| Amazon_linux | — | Upgrade mod24_auth_mellonUpgrade mod_auth_mellon | Jan 10, 2020 | Jun 29, 2019 |
| Centos_linux | — | Upgrade mod_auth_mellonUpgrade mod_auth_mellon-diagnostics-debuginfoUpgrade mod_auth_mellon-debuginfoUpgrade mod_auth_mellon-debugsourceUpgrade mod_auth_mellon-diagnostics | Apr 1, 2020 | Jun 29, 2019 |
| Debian | — | Upgrade libapache2-mod-auth-mellon | Mar 14, 2023 | Jun 29, 2019 |
| Freebsd | — | Upgrade mod_auth_mellon | Nov 4, 2022 | Sep 22, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mod_auth_mellon | Jun 17, 2022 | Jun 29, 2019 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-mellon to version 0.16.0-11.4.20.0.1.3.0 on Solaris 11.4 | Jan 19, 2021 | Jun 29, 2019 |
| Oracle_linux | — | Upgrade mod_auth_mellon-diagnosticsUpgrade mod_auth_mellon | Oct 5, 2022 | Jun 20, 2019 |
| Redhat_linux | — | Upgrade mod_auth_mellon-debugsourceUpgrade mod_auth_mellon-diagnostics-debuginfoUpgrade mod_auth_mellon-debuginfoNo solution existsUpgrade mod_auth_mellonUpgrade mod_auth_mellon-diagnostics | Apr 1, 2020 | Jun 29, 2019 |
| Ubuntu | — | Upgrade libapache2-mod-auth-mellon | Mar 2, 2020 | Jun 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub