CVE-2019-13038
29.06.2019, 14:15
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
| Vendor | Product | Version |
|---|---|---|
| mod_auth_mellon_project | mod_auth_mellon | 𝑥 ≤ 0.14.2 |
| oracle | zfs_storage_appliance_kit | 8.8 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libapache2-mod-auth-mellon |
|
Common Weakness Enumeration
References