Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20479

Опубликовано: 12 нояб. 2019
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

An open redirect flaw was discovered in mod_auth_openidc where it handles logout redirection. The module does not correctly validate the URL, allowing a URL with slash and backslash at the beginning to bypass the protection checks. A victim user may be tricked into visiting a trusted vulnerable web site, which would redirect him to another, possibly malicious, URL.

Отчет

It is not possible to reproduce the open redirect vulnerability in the versions of mod_auth_openidc as shipped in Red Hat Enterprise Linux 7, as a missing check makes the process crash, due to a NULL pointer dereference, instead of letting it continue with an invalid URL.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1805102mod_auth_openidc: Open redirect issue exists in URLs with slash and backslash

EPSS

Процентиль: 64%
0.00474
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

CVSS3: 6.1
nvd
больше 5 лет назад

A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.

CVSS3: 6.1
debian
больше 5 лет назад

A flaw was found in mod_auth_openidc before version 2.4.1. An open red ...

suse-cvrf
около 5 лет назад

Security update for apache2-mod_auth_openidc

suse-cvrf
больше 5 лет назад

Security update for apache2-mod_auth_openidc

EPSS

Процентиль: 64%
0.00474
Низкий

6.1 Medium

CVSS3