Lucene search

K
osvGoogleOSV:USN-4597-1
HistoryOct 22, 2020 - 12:47 p.m.

libapache2-mod-auth-mellon vulnerabilities

2020-10-2212:47:17
Google
osv.dev
4

6.7 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%

François Kooman discovered that mod_auth_mellon incorrectly handled
cookies. An attacker could possibly use this issue to cause a Cross-Site
Session Transfer attack. (CVE-2017-6807)

It was discovered that mod_auth_mellon incorrectly handled certain requests.
An attacker could possibly use this issue to redirect a user to a malicious
URL. (CVE-2019-3877)

It was discovered that mod_auth_mellon incorrectly handled certain requests.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-3878)