Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13038

Опубликовано: 20 июн. 2019
Источник: redhat
CVSS3: 6.1

Описание

mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6mod_auth_mellonOut of support scope
Red Hat Software Collectionshttpd24-mod_auth_mellonWill not fix
Red Hat Enterprise Linux 7mod_auth_mellonFixedRHSA-2020:100331.03.2020
Red Hat Enterprise Linux 8mod_auth_mellonFixedRHSA-2020:166028.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1725740mod_auth_mellon: Open Redirect via the login?ReturnTo= substring which could facilitate information theft

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

CVSS3: 6.1
nvd
больше 6 лет назад

mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

CVSS3: 6.1
debian
больше 6 лет назад

mod_auth_mellon through 0.14.2 has an Open Redirect via the login?Retu ...

CVSS3: 6.1
github
больше 3 лет назад

mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

oracle-oval
почти 6 лет назад

ELSA-2020-1660: mod_auth_mellon security and bug fix update (MODERATE)

6.1 Medium

CVSS3