CVE-2019-3878

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 26 Mar 2019, 17:44
Last modified:04 Aug 2024, 19:19

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
8.1 HIGH
v3.0 (cve.org)
EPSS Score
2.01% LOW
2% probability -1.14%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

26 Mar 2019, 17:44
Published
Vulnerability first disclosed
04 Aug 2024, 19:19
Last Modified
Vulnerability information updated

Description

A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.

CVSS Metrics

  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 2.01% Percentile: 84%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-305Authentication Bypass by Primary Weakness

    The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Affected Systems

  • canonicalubuntu_linux

    18.04 | 18.10

  • fedoraprojectfedora

    29 | 30

  • mod_auth_mellon_projectmod_auth_mellon

    < 0.14.2

  • redhatenterprise_linux

    7.0

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_server

    7.0

  • redhatenterprise_linux_server_aus

    7.6

  • redhatenterprise_linux_server_eus

    7.6

  • redhatenterprise_linux_server_tus

    7.6

  • redhatenterprise_linux_workstation

    7.0

  • uninettmod_auth_mellon

    < v0.14.2

References (9)