Uninett mod_auth_mellon Module CVE-2019-3878 Authentication Bypass Vulnerability
BID:108179
Info
Uninett mod_auth_mellon Module CVE-2019-3878 Authentication Bypass Vulnerability
| Bugtraq ID: | 108179 |
| Class: | Design Error |
| CVE: |
CVE-2019-3878 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2018 12:00AM |
| Updated: | May 10 2018 12:00AM |
| Credit: | jhrozek |
| Vulnerable: |
Uninett mod_auth_mellon 0.13.1 Uninett mod_auth_mellon 0.11 Uninett mod_auth_mellon 0.8.1 Uninett mod_auth_mellon 0.8 Uninett mod_auth_mellon 0.11.1 Redhat Software Collections 1 for RHEL Workstation 7 0 Redhat Software Collections 1 for RHEL Workstation 6 0 Redhat Software Collections 1 for RHEL 7 0 Redhat Software Collections 1 for RHEL 7.6 Redhat Software Collections 1 for RHEL 7.5 Redhat Software Collections 1 for RHEL 7.4 Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Server - Update Services for SAP Solutions 7.6 Redhat Enterprise Linux Server - TUS 7.6 Redhat Enterprise Linux Server - Extended Update Support 7.6 Redhat Enterprise Linux Server - AUS 7.6 Redhat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions 7. Redhat Enterprise Linux Server 7 Redhat Enterprise Linux for x86_64 8 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.6 Redhat Enterprise Linux for Power, little endian 7 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.6 Redhat Enterprise Linux for Power, big endian 7 Redhat Enterprise Linux for Power little endian 8 Redhat Enterprise Linux for Power 9 7 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.6 Redhat Enterprise Linux for IBM z Systems 8 Redhat Enterprise Linux for IBM z Systems 7 Redhat Enterprise Linux for IBM System z (Structure A) 7 Redhat Enterprise Linux for ARM 64 7 Redhat Enterprise Linux for ARM 64 8 |
| Not Vulnerable: |
Uninett mod_auth_mellon 0.14.2 |
Discussion
Uninett mod_auth_mellon Module CVE-2019-3878 Authentication Bypass Vulnerability
Uninett mod_auth_mellon module is prone to an unspecified authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access. This may aid in further attacks.
Uninett mod_auth_mellon module is prone to an unspecified authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access. This may aid in further attacks.
Exploit / POC
Uninett mod_auth_mellon Module CVE-2019-3878 Authentication Bypass Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Uninett mod_auth_mellon Module CVE-2019-3878 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Uninett mod_auth_mellon Module CVE-2019-3878 Authentication Bypass Vulnerability
References:
References:
- Modify am_handler setup to run before mod_proxy #196 (Uninett)
- Bug 1691126 (CVE-2019-3878) - CVE-2019-3878 mod_auth_mellon: authentication byp (Redhat)
- CVE-2019-3878 (Redhat)
- RHSA-2019:0746 - Security Advisory (Redhat)
- RHSA-2019:0766 - Security Advisory (Redhat)
- RHSA-2019:0985 - Security Advisory (Redhat)
- Uninett Homepage (Uninett)