Description
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-15861 | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site. |
Ubuntu USN |
USN-4597-1 | mod_auth_mellon vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:41:17.546Z
Reserved: 2017-03-10T00:00:00.000Z
Link: CVE-2017-6807
No data.
Status : Deferred
Published: 2017-03-13T14:59:00.177
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-6807
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN