Логотип exploitDog
bind:CVE-2019-3877
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-3877

Количество 8

Количество 8

ubuntu логотип

CVE-2019-3877

почти 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2019-3877

почти 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-3877

почти 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2019-3877

почти 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open r ...

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-qr9h-f4fq-2h85

больше 3 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
EPSS: Низкий
oracle-oval логотип

ELSA-2019-3421

около 6 лет назад

ELSA-2019-3421: mod_auth_mellon security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2019-01561

почти 7 лет назад

Уязвимость модуля аутентификации mod_auth_mellon сервера Apache HTTP Server, связанная с ошибками преобразования символов «\», позволяющая нарушителю перенаправить пользователя на вредоносный сайт

CVSS3: 6.1
EPSS: Низкий
oracle-oval логотип

ELSA-2019-0766

почти 7 лет назад

ELSA-2019-0766: mod_auth_mellon security and bug fix update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
1%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open r ...

CVSS3: 5.8
1%
Низкий
почти 7 лет назад
github логотип
GHSA-qr9h-f4fq-2h85

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2019-3421

ELSA-2019-3421: mod_auth_mellon security, bug fix, and enhancement update (MODERATE)

около 6 лет назад
fstec логотип
BDU:2019-01561

Уязвимость модуля аутентификации mod_auth_mellon сервера Apache HTTP Server, связанная с ошибками преобразования символов «\», позволяющая нарушителю перенаправить пользователя на вредоносный сайт

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
oracle-oval логотип
ELSA-2019-0766

ELSA-2019-0766: mod_auth_mellon security and bug fix update (IMPORTANT)

почти 7 лет назад

Уязвимостей на страницу