CVE-2019-3878: High severity Mod Auth Mellon Project Mod Auth Mellon Apache vulnerability
A vulnerability was found in modauthmellon before v0.14.2. If Apache is configured as a reverse proxy and modauthmellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.
Other sources
A vulnerability was found in modauthmellon. If Apache is configured as a reverse proxy and modauthmellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.
References: https://bugzilla.redhat.com/showbug.cgi?id=1576719
Upstream Patch: https://github.com/Uninett/modauthmellon/pull/196
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3878?
The severity of CVE-2019-3878 is high with a CVSS score of 8.1.
How does the vulnerability CVE-2019-3878 affect mod_auth_mellon?
The vulnerability CVE-2019-3878 affects mod_auth_mellon versions before v0.14.2.
What is the recommended version to fix CVE-2019-3878?
To fix CVE-2019-3878, it is recommended to update to mod_auth_mellon v0.14.2 or later.
How can I mitigate the risk of CVE-2019-3878?
To mitigate the risk of CVE-2019-3878, you should update mod_auth_mellon to version 0.14.2 or apply the necessary patches.
Are there any references available for CVE-2019-3878?
Yes, you can find references for CVE-2019-3878 at the following links: [link1], [link2], [link3].