CVE-2021-3639

Publication date 4 August 2021

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.1 · Medium

Score breakdown

A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.

Status

Package Ubuntu Release Status
libapache2-mod-auth-mellon 24.10 oracular
Fixed 0.17.0-1ubuntu1
24.04 LTS noble
Fixed 0.17.0-1ubuntu1
23.10 mantic
Fixed 0.17.0-1ubuntu1
23.04 lunar
Fixed 0.17.0-1ubuntu1
22.10 kinetic
Fixed 0.17.0-1ubuntu1
22.04 LTS jammy
Fixed 0.17.0-1ubuntu1
21.10 impish
Fixed 0.17.0-1ubuntu1
21.04 hirsute
Fixed 0.17.0-1ubuntu0.21.04.1
20.04 LTS focal
Fixed 0.16.0-1ubuntu0.1
18.04 LTS bionic
Fixed 0.13.1-1ubuntu0.3
16.04 LTS xenial
Vulnerable
14.04 LTS trusty Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libapache2-mod-auth-mellon

Severity score breakdown

Parameter Value
Base score 6.1 · Medium
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Changed
Confidentiality Low
Integrity impact Low
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Related Ubuntu Security Notices (USN)

    • USN-5069-1
    • mod-auth-mellon vulnerability
    • 8 September 2021
    • USN-5069-2
    • mod-auth-mellon vulnerability
    • 8 September 2021

Other references