CVE-2019-3877 Details
Description
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mod auth mellon project mod auth mellon | < 0.14.2 |
CPE
Remediation
| |
| fedoraproject fedora | 29 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 |
CPE
Remediation
| |
| canonical ubuntu linux | 18.04 18.10 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Nov 6, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Apr 16, 2019 | CVE Modified | [email protected] |
| Apr 10, 2019 | CVE Modified | [email protected] |
| Apr 3, 2019 | Modified Analysis | [email protected] |
| Apr 2, 2019 | CVE Modified | [email protected] |
| Mar 28, 2019 | CVE Modified | [email protected] |
| Mar 28, 2019 | Initial Analysis | [email protected] |