Description
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
References (8)
Core 8
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3877
Patch, Third Party Advisory x_refsource_confirm
https://github.com/Uninett/mod_auth_mellon/issues/35
Patch, Third Party Advisory x_refsource_confirm
https://github.com/Uninett/mod_auth_mellon/commit/62041428a32de402e0be6ba45fe12df6a83bedb8
Third Party Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3924-1/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNW5YMC5TLWVWNJEY6AIWNSNPRAMWPQJ/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X7NLAU7KROWNTHAYSA2S67X347F42L2I/
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0766
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3421
Scores
CVSS v3
5.8
EPSS
0.0081
EPSS Percentile
74.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (5)
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
18.10
fedoraproject/fedora
29
mod_auth_mellon_project/mod_auth_mellon
< 0.14.2
redhat/enterprise_linux
7.0
Published
Mar 27, 2019
Tracked Since
Feb 18, 2026