Source: libapache2-mod-auth-mellon
Version: 0.14.1-1
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://github.com/Uninett/mod_auth_mellon/pull/196
Control: found -1 0.12.0-2

Hi,

The following vulnerability was published for libapache2-mod-auth-mellon.

CVE-2019-3878[0]:
authentication bypass in ECP flow

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-3878
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3878
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1576719
[2] https://github.com/Uninett/mod_auth_mellon/pull/196
[3] 
https://github.com/Uninett/mod_auth_mellon/commit/e09a28a30e13e5c22b481010f26b4a7743a09280

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to