Mod Auth Mellon Project develops a focused SAML authentication module for Apache HTTP Server, a critical component in federated identity and single sign-on deployments across enterprises. Its vulnerability surface centers on the module's authentication and redirection logic, with recurring exposures in open-redirect flaws, authentication bypass conditions, and improper authentication handling that reflect the complexity of SAML protocol state management. Current severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mod Auth Mellon Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3878HIGH A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (w | Mar 26, 2019 | 8.1 | 26 | NO | NO |
CVE-2019-13038MEDIUM mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. | Jun 29, 2019 | 6.1 | 22 | NO | NO |
CVE-2019-3877MEDIUM A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative U | Mar 27, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mod Auth Mellon Project.
Media articles that mention a CVE ID that affects a product developed by Mod Auth Mellon Project — matched by CVE ID, not by vendor name.