Description
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3359-1 | libapache2-mod-auth-mellon security update |
EUVD |
EUVD-2021-26939 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity. |
Ubuntu USN |
USN-5069-1 | mod-auth-mellon vulnerability |
Ubuntu USN |
USN-5069-2 | mod-auth-mellon vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.702Z
Reserved: 2021-07-09T00:00:00.000Z
Link: CVE-2021-3639
No data.
Status : Modified
Published: 2022-08-22T15:15:13.633
Modified: 2024-11-21T06:22:02.930
Link: CVE-2021-3639
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN