ZeroHour

CVE-2019-3878

PoC
CVSS 3.0
8.1 high
EPSS
3%p86
Published
()
Modified
Description

A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.

Vendors
mod auth mellon projectfedoraprojectredhatcanonical
Products
mod auth mellon, fedora, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, ubuntu linux
Weakness
CWE-305, CWE-287
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.