Bugzilla – Bug 1188926
VUL-0: CVE-2021-3639: apache2-mod_auth_mellon: Open Redirect vulnerability in logout URLs
Last modified: 2024-07-26 10:27:32 UTC
rh#1980648 A vulnerability was found in mod_auth_mellon where it does not sanatize logout URLs properly results in phishing attacks by tricking users. References: https://bugzilla.redhat.com/show_bug.cgi?id=1980648 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3639 https://github.com/latchset/mod_auth_mellon/commit/42a11261b9dad2e48d70bdff7c53dd57a12db6f5
tracking as affected: - SUSE:SLE-12-SP5:Update/apache2-mod_auth_mellon
# maintenance_jira_update_notice SUSE-SU-2021:2912-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1188926 CVE References: CVE-2021-3639 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP5 (src): apache2-mod_auth_mellon-0.16.0-8.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:1524-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1188926 CVE References: CVE-2021-3639 JIRA References: Sources used: openSUSE Leap 15.4 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 openSUSE Leap 15.3 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Manager Server 4.1 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Manager Retail Branch Server 4.1 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Manager Proxy 4.1 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise Module for Server Applications 15-SP4 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise Module for Server Applications 15-SP3 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 SUSE Enterprise Storage 7 (src): apache2-mod_auth_mellon-0.17.0-150200.5.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All done, closing.