Lucene search

K
ubuntuUbuntuUSN-4597-1
HistoryOct 22, 2020 - 12:00 a.m.

mod_auth_mellon vulnerabilities

2020-10-2200:00:00
ubuntu.com
75
ubuntu 16.04 esm
libapache2-mod-auth-mellon
saml 2.0 authentication
cross-site session transfer attack
cve-2017-6807
malicious url
cve-2019-3877
sensitive information
cve-2019-3878
unix

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.022

Percentile

89.6%

Releases

  • Ubuntu 16.04 ESM

Packages

  • libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache

Details

François Kooman discovered that mod_auth_mellon incorrectly handled
cookies. An attacker could possibly use this issue to cause a Cross-Site
Session Transfer attack. (CVE-2017-6807)

It was discovered that mod_auth_mellon incorrectly handled certain requests.
An attacker could possibly use this issue to redirect a user to a malicious
URL. (CVE-2019-3877)

It was discovered that mod_auth_mellon incorrectly handled certain requests.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-3878)

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchlibapache2-mod-auth-mellon< 0.12.0-2+deb9u1build0.16.04.1UNKNOWN
Ubuntu16.04noarchlibapache2-mod-auth-mellon-dbgsym< 0.12.0-2+deb9u1build0.16.04.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.022

Percentile

89.6%