Medium severity6.1NVD Advisory· Published Jun 29, 2019· Updated Jun 17, 2026
CVE-2019-13038
CVE-2019-13038
Description
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- mod_auth_mellon/mod_auth_mellondescription
- Range: <=0.14.2
Patches
Vulnerability mechanics
References
6- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- github.com/Uninett/mod_auth_mellon/issues/35nvdIssue TrackingThird Party Advisory
- usn.ubuntu.com/4291-1/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/03/msg00010.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5E3JVHURJJNDP63CKVX5O5MJAGCQV4K/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XU5GVFZW3C2M4ZBL4F7UP7N24FNUCX4E/nvd
News mentions
0No linked articles in our index yet.