CVE-2019-13038
29.06.2019, 14:15
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
Vendor | Product | Version |
---|---|---|
mod_auth_mellon_project | mod_auth_mellon | 𝑥 ≤ 0.14.2 |
oracle | zfs_storage_appliance_kit | 8.8 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libapache2-mod-auth-mellon |
|
Common Weakness Enumeration
References