Описание
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | mod_auth_mellon | Out of support scope | ||
Red Hat Enterprise Linux 7 | mod_auth_mellon | Out of support scope | ||
Red Hat Enterprise Linux 9 | mod_auth_mellon | Not affected | ||
Red Hat Software Collections | httpd24-mod_auth_mellon | Will not fix | ||
Red Hat Enterprise Linux 8 | mod_auth_mellon | Fixed | RHSA-2022:1934 | 10.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
A flaw was found in mod_auth_mellon where it does not sanitize logout ...
EPSS
6.1 Medium
CVSS3