zoukankan      html  css  js  c++  java
  • Debian Security Advisory(Debian安全报告) DSA-4414-1 libapache2-mod-auth-mellon security update

    Debian Security Advisory(Debian安全报告) DSA-4414-1 libapache2-mod-auth-mellon security update

    Package:libapache2-mod-auth-mellon

    CVE ID::CVE-2019-3877 CVE-2019-3878

    Debian Bug: 925197


      在提供SAML 2.0身份验证的Apache模块auth_mellon中发现了几个问题。

    cve - 2019 - 3877

      可以在注销时绕过重定向URL检查,因此该模块可以用作开放重定向工具。

    cve - 2019 - 3878

      当在Apache配置中使用mod_auth_mellon作为http_proxy模块的远程代理时,可以通过发送SAML ECP头来绕过身份验证。

      这些问题在0.12.0-2+deb9u1版本中得到了修复。

      有关libapache2-mod-auto-mellon的详细安全情况,请参阅其安全跟踪器页面:https://securtracker.debian.org/tracker/libapache2 -mod- auto -mellon

    --------------------

    Debian Security Advisory DSA-4414-1 libapache2-mod-auth-mellon security update

    Package        : libapache2-mod-auth-mellon
    CVE ID         : CVE-2019-3877 CVE-2019-3878
    Debian Bug     : 925197

    Several issues have been discovered in Apache module auth_mellon, which provides SAML 2.0 authentication.

    CVE-2019-3877
        It was possible to bypass the redirect URL checking on logout, so 
    the module could be used as an open redirect facility.

    CVE-2019-3878
        When mod_auth_mellon is used in an Apache configuration which 
    serves as a remote proxy with the http_proxy module, it was possible to bypass authentication by sending SAML ECP headers.

    These problems have been fixed in version 0.12.0-2+deb9u1.

    For the detailed security status of libapache2-mod-auth-mellon please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libapache2-mod-auth-mellon

  • 相关阅读:
    define的用法
    MySQL索引使用方法和性能优化
    自己写的一个Js小插件
    .net处理JSON简明教程
    史上最全的ASP.NET MVC路由配置,以后RouteConfig再弄不懂神仙都难救你啦~
    Python面向对象之-反射
    Python内置函数之classmetho staticmethod
    Python内置函数之-property
    python面向对象三大特性-多态
    python面向对象三大特性之封装
  • 原文地址:https://www.cnblogs.com/iAmSoScArEd/p/10595433.html
Copyright © 2011-2022 走看看