A flaw was found in modauthmellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
[
{
"signature_type": "Function",
"digest": {
"function_hash": "83105587025666378258602412050770007892",
"length": 455.0
},
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "am_check_url",
"file": "auth_mellon_util.c"
},
"source": "https://github.com/latchset/mod_auth_mellon/commit/42a11261b9dad2e48d70bdff7c53dd57a12db6f5",
"id": "CVE-2021-3639-06f962b5"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"280196004057991006795901954659145925227",
"61501412547766912992816068119698943885",
"121989369976254605987379571555865310157",
"28373241189536936529294675472970530512",
"210226503878164329466142730749373246164",
"144331043775858122924234340824680977387"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "auth_mellon_util.c"
},
"source": "https://github.com/latchset/mod_auth_mellon/commit/42a11261b9dad2e48d70bdff7c53dd57a12db6f5",
"id": "CVE-2021-3639-cc818928"
}
]