UBUNTU-CVE-2021-3639
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3639
UBUNTU-CVE-2021-3639
Summary:
Details: A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
References: https://ubuntu.com/security/CVE-2021-3639, https://ubuntu.com/security/notices/USN-5069-1, https://ubuntu.com/security/notices/USN-5069-2, https://www.cve.org/CVERecord?id=CVE-2021-3639
Affected packages
Package
Name: libapache2-mod-auth-mellon
Purl: pkg:deb/ubuntu/[email protected]+deb9u1build0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
