CVE-2019-3877

MEDIUM

Mod Auth Mellon < 0.14.2 - Open Redirect

Title source: rule
STIX 2.1

Description

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

References (8)

Core 8
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3877
Patch, Third Party Advisory x_refsource_confirm
https://github.com/Uninett/mod_auth_mellon/issues/35
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3924-1/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0766
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3421

Scores

CVSS v3 5.8
EPSS 0.0081
EPSS Percentile 74.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Details

CWE
CWE-601
Status published
Products (5)
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
fedoraproject/fedora 29
mod_auth_mellon_project/mod_auth_mellon < 0.14.2
redhat/enterprise_linux 7.0
Published Mar 27, 2019
Tracked Since Feb 18, 2026