A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3359-1 | libapache2-mod-auth-mellon security update |
EUVD |
EUVD-2021-26939 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity. |
Ubuntu USN |
USN-5069-1 | mod-auth-mellon vulnerability |
Ubuntu USN |
USN-5069-2 | mod-auth-mellon vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.702Z
Reserved: 2021-07-09T00:00:00.000Z
Link: CVE-2021-3639
No data.
Status : Modified
Published: 2022-08-22T15:15:13.633
Modified: 2024-11-21T06:22:02.930
Link: CVE-2021-3639
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN