漏洞信息详情
mod_auth_mellon 授权问题漏洞
漏洞简介
mod_auth_mellon是一款使用在Apache中的身份验证模块。
mod_auth_mellon中存在安全漏洞。攻击者可利用该漏洞绕过身份验证。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/Uninett/mod_auth_mellon/commit/e09a28a30e13e5c22b481010f26b4a7743a09280
参考网址
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3878
来源:REDHAT
链接:https://access.redhat.com/errata/RHBA-2019:0959
来源:CONFIRM
链接:https://github.com/Uninett/mod_auth_mellon/pull/196
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/CNW5YMC5TLWVWNJEY6AIWNSNPRAMWPQJ/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0985
来源:UBUNTU
链接:https://usn.ubuntu.com/3924-1/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/X7NLAU7KROWNTHAYSA2S67X347F42L2I/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0746
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:0766
来源:www.debian.org
链接:http://www.debian.org/security/2019/dsa-4414
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:0985
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/3924-1/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152202/Debian-Security-Advisory-4414-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/78058
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152281/Ubuntu-Security-Notice-USN-3924-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159676/Ubuntu-Security-Notice-USN-4597-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/77698
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-mod-auth-mellon-privilege-escalation-via-SAML-ECP-Headers-28829
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-3878
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3653/
受影响实体
暂无
补丁
- mod_auth_mellon 安全漏洞的修复措施<!--2019-3-25-->
还没有评论,来说两句吧...