Количество 8
Количество 8
CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open r ...
GHSA-qr9h-f4fq-2h85
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
ELSA-2019-3421
ELSA-2019-3421: mod_auth_mellon security, bug fix, and enhancement update (MODERATE)
BDU:2019-01561
Уязвимость модуля аутентификации mod_auth_mellon сервера Apache HTTP Server, связанная с ошибками преобразования символов «\», позволяющая нарушителю перенаправить пользователя на вредоносный сайт
ELSA-2019-0766
ELSA-2019-0766: mod_auth_mellon security and bug fix update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-3877 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function. | CVSS3: 5.8 | 1% Низкий | почти 7 лет назад | |
CVE-2019-3877 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function. | CVSS3: 6.1 | 1% Низкий | почти 7 лет назад | |
CVE-2019-3877 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function. | CVSS3: 5.8 | 1% Низкий | почти 7 лет назад | |
CVE-2019-3877 A vulnerability was found in mod_auth_mellon before v0.14.2. An open r ... | CVSS3: 5.8 | 1% Низкий | почти 7 лет назад | |
GHSA-qr9h-f4fq-2h85 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
ELSA-2019-3421 ELSA-2019-3421: mod_auth_mellon security, bug fix, and enhancement update (MODERATE) | около 6 лет назад | |||
BDU:2019-01561 Уязвимость модуля аутентификации mod_auth_mellon сервера Apache HTTP Server, связанная с ошибками преобразования символов «\», позволяющая нарушителю перенаправить пользователя на вредоносный сайт | CVSS3: 6.1 | 1% Низкий | почти 7 лет назад | |
ELSA-2019-0766 ELSA-2019-0766: mod_auth_mellon security and bug fix update (IMPORTANT) | почти 7 лет назад |
Уязвимостей на страницу