CVE-2021-3639
Summary
| CVE | CVE-2021-3639 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-22 15:15:00 UTC |
| Updated | 2023-02-12 23:41:00 UTC |
| Description | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Prevent redirect to URLs that begin with '///' · latchset/mod_auth_mellon@42a1126 · GitHub |
MISC |
github.com |
|
| 1980648 – (CVE-2021-3639) CVE-2021-3639 mod_auth_mellon: Open Redirect vulnerability in logout URLs |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159805 Oracle Enterprise Linux Security Update for mod_auth_mellon (ELSA-2022-1934)
- 181385 Debian Security Update for libapache2-mod-auth-mellon (CVE-2021-3639)
- 181628 Debian Security Update for libapache2-mod-auth-mellon (DLA 3359-1)
- 198485 Ubuntu Security Notification for mod-auth-mellon Vulnerability (USN-5069-2)
- 198496 Ubuntu Security Notification for mod-auth-mellon Vulnerability (USN-5069-1)
- 240312 Red Hat Update for mod_auth_mellon (RHSA-2022:1934)
- 282204 Fedora Security Update for mod_auth_mellon (FEDORA-2021-5e033d6641)
- 282229 Fedora Security Update for mod_auth_mellon (FEDORA-2022-b18f01985a)
- 355386 Amazon Linux Security Advisory for mod_auth_mellon : ALAS2-2023-2077
- 355426 Amazon Linux Security Advisory for mod24_auth_mellon : ALAS-2023-1765
- 670753 EulerOS Security Update for mod_auth_mellon (EulerOS-SA-2021-2511)
- 671018 EulerOS Security Update for mod_auth_mellon (EulerOS-SA-2021-2597)
- 671432 EulerOS Security Update for mod_auth_mellon (EulerOS-SA-2022-1354)
- 751076 SUSE Enterprise Linux Security Update for apache2-mod_auth_mellon (SUSE-SU-2021:2912-1)
- 752106 SUSE Enterprise Linux Security Update for apache2-mod_auth_mellon (SUSE-SU-2022:1524-1)
- 903886 Common Base Linux Mariner (CBL-Mariner) Security Update for mod_auth_mellon (10651)
- 907262 Common Base Linux Mariner (CBL-Mariner) Security Update for mod_auth_mellon (10651-1)
- 940560 AlmaLinux Security Update for mod_auth_mellon (ALSA-2022:1934)
- 960334 Rocky Linux Security Update for mod_auth_mellon (RLSA-2022:1934)