Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.883036
Category:CentOS Local Security Checks
Title:CentOS: Security Advisory for mod_auth_mellon (CESA-2019:0766)
Summary:The remote host is missing an update for the 'mod_auth_mellon'; package(s) announced via the CESA-2019:0766 advisory.
Description:Summary:
The remote host is missing an update for the 'mod_auth_mellon'
package(s) announced via the CESA-2019:0766 advisory.

Vulnerability Insight:
The mod_auth_mellon module for the Apache HTTP Server is an authentication
service that implements the SAML 2.0 federation protocol. The module grants
access based on the attributes received in assertions generated by an IdP
server.

Security Fix(es):

* mod_auth_mellon: authentication bypass in ECP flow (CVE-2019-3878)

* mod_auth_mellon: open redirect in logout url when using URLs with
backslashes (CVE-2019-3877)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

* mod_auth_mellon Cert files name wrong when hostname contains a number
(fixed in upstream package) (BZ#1697487)

Affected Software/OS:
'mod_auth_mellon' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-3877
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7NLAU7KROWNTHAYSA2S67X347F42L2I/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNW5YMC5TLWVWNJEY6AIWNSNPRAMWPQJ/
RedHat Security Advisories: RHSA-2019:0766
https://access.redhat.com/errata/RHSA-2019:0766
RedHat Security Advisories: RHSA-2019:3421
https://access.redhat.com/errata/RHSA-2019:3421
https://usn.ubuntu.com/3924-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-3878
RedHat Security Advisories: RHBA-2019:0959
https://access.redhat.com/errata/RHBA-2019:0959
RedHat Security Advisories: RHSA-2019:0746
https://access.redhat.com/errata/RHSA-2019:0746
RedHat Security Advisories: RHSA-2019:0985
https://access.redhat.com/errata/RHSA-2019:0985
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.