CVE-2019-13038 is an Open Redirect vulnerability affecting mod_auth_mellon through version 0.14.2, as well as products from Canonical, Fedora Project, and Oracle. This flaw allows an attacker to redirect users to arbitrary external sites by manipulating the "login?ReturnTo=" parameter, specifically by omitting the double slash in the target URL. Rated as MEDIUM severity with a CVSS score of 6.1, this vulnerability requires user interaction (UI:R) and can lead to information disclosure (C:L) and integrity loss (I:L), primarily through phishing attacks. The attack complexity is low (AC:L), and it can be exploited over the network (AV:N). Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.14.2CPE matchmatch criteria | cpe:2.3:a:mod_auth_mellon_project:mod_auth_mellon:*:*:*:*:*:apache:*:* | ||
8.8CPE matchmatch criteria | cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.