Uninett mod_auth_mellon Module CVE-2019-3877 Open Redirection Vulnerability
BID:107556
Info
Uninett mod_auth_mellon Module CVE-2019-3877 Open Redirection Vulnerability
| Bugtraq ID: | 107556 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-3877 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2019 12:00AM |
| Updated: | Mar 22 2019 12:00AM |
| Credit: | garudlaksha1 c |
| Vulnerable: |
Uninett mod_auth_mellon 0 Redhat Software Collections for RHEL 0 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 |
| Not Vulnerable: | |
Discussion
Uninett mod_auth_mellon Module CVE-2019-3877 Open Redirection Vulnerability
Uninett mod_auth_mellon Module is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks or gain sensitive information. Other attacks are possible.
Uninett mod_auth_mellon Module is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks or gain sensitive information. Other attacks are possible.
Exploit / POC
Uninett mod_auth_mellon Module CVE-2019-3877 Open Redirection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Uninett mod_auth_mellon Module CVE-2019-3877 Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Uninett mod_auth_mellon Module CVE-2019-3877 Open Redirection Vulnerability
References:
References:
- Fix redirect URL validation bypass (Uninett)
- Open Redirection issue #35 (Uninett)
- mod_auth_mellon Homepage (Uninett)
- Bug 1691125 (CVE-2019-3877) - CVE-2019-3877 mod_auth_mellon: open redirect in l (Redhat)
- CVE-2019-3877 (Redhat)