Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-1934

Опубликовано: 17 мая 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-1934: mod_auth_mellon security update (MODERATE)

[0.14.0-12.1]

  • Resolves: rhbz#1986805 - CVE-2021-3639 mod_auth_mellon: Open Redirect vulnerability in logout URLs [rhel-8]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

mod_auth_mellon

0.14.0-12.el8.1

mod_auth_mellon-diagnostics

0.14.0-12.el8.1

Oracle Linux x86_64

mod_auth_mellon

0.14.0-12.el8.1

mod_auth_mellon-diagnostics

0.14.0-12.el8.1

Связанные CVE

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.

CVSS3: 6.1
redhat
около 4 лет назад

A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.

CVSS3: 6.1
nvd
почти 3 года назад

A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.

CVSS3: 6.1
debian
почти 3 года назад

A flaw was found in mod_auth_mellon where it does not sanitize logout ...

suse-cvrf
больше 3 лет назад

Security update for apache2-mod_auth_mellon