mod_auth_mellon: authentication bypass in ECP flow
Published Mar 26, 2019
8.1
HIGHCVSS 3.0
EPSS 2.97%
Description
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.
Affected products
-
- Version before v0.14.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Uninett | Mod Auth Mellon | n/a |
|
Configuration 1
- < 0.14.2
Configuration 2
- 29
- 30
Configuration 3
- 7.0
- 7.0
- 7.0
- 7.6
- 7.6
- 7.6
- 7.0
Configuration 4
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 7
mod_auth_mellon-0:0.14.0-2.el7_6.4
Fixed · RHSA-2019:0766
Red Hat Enterprise Linux 8
mod_auth_mellon-0:0.14.0-3.el8_0.2
Fixed · RHSA-2019:0985
Red Hat Software Collections for Red Hat Enterprise Linux 6
httpd24-httpd-0:2.4.34-7.el6.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7
httpd24-httpd-0:2.4.34-7.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7
httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
httpd24-httpd-0:2.4.34-7.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
httpd24-httpd-0:2.4.34-7.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
httpd24-httpd-0:2.4.34-7.el7.1
Fixed · RHSA-2019:0746
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
Fixed · RHSA-2019:0746
Red Hat Enterprise Linux 6
mod_auth_mellon
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | mod_auth_mellon-0:0.14.0-2.el7_6.4 | Fixed | RHSA-2019:0766 |
| Red Hat Enterprise Linux 8 | mod_auth_mellon-0:0.14.0-3.el8_0.2 | Fixed | RHSA-2019:0985 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-httpd-0:2.4.34-7.el6.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | httpd24-httpd-0:2.4.34-7.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | httpd24-mod_auth_mellon-0:0.13.1-2.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | httpd24-httpd-0:2.4.34-7.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | httpd24-mod_auth_mellon-0:0.13.1-2.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | httpd24-httpd-0:2.4.34-7.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | httpd24-mod_auth_mellon-0:0.13.1-2.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | httpd24-httpd-0:2.4.34-7.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | httpd24-mod_auth_mellon-0:0.13.1-2.el7.1 | Fixed | RHSA-2019:0746 |
| Red Hat Enterprise Linux 6 | mod_auth_mellon | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of mod_auth_mellon as shipped with Red Hat Enterprise Linux 6 as they did not include support for ECP.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (20 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 2.97% (0.02969) | 86.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.97% (0.02969) | 85.42th | v5 (v2026.06.15) |
| Apr 13, 2026 | 2.01% (0.02011) | 83.70th | v4 (v2025.03.14) |
| May 21, 2025 | 3.21% (0.03208) | 86.39th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.62% (0.00618) | 67.50th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.09% (0.02088) | 73.35th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.62% (0.00618) | 68.18th | v4 (v2025.03.14) |
| Dec 17, 2024 | 0.95% (0.00946) | 82.93th | v3 (v2023.03.01) |
| Mar 19, 2024 | 1.76% (0.01763) | 87.69th | v3 (v2023.03.01) |
| Feb 15, 2024 | 1.47% (0.01468) | 86.34th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.37% (0.01369) | 84.76th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.55% (0.00548) | 74.57th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.67% (0.00666) | 76.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 20.27% (0.20271) | 94.02th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.15% (0.09152) | 86.58th | v1 |
| Jan 6, 2022 | 9.15% (0.09152) | 86.43th | v1 |
| Jan 5, 2022 | 2.20% (0.02196) | 78.23th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.20% (0.02196) | 0.00th | v1 |
References (13)
- https://access.redhat.com/errata/RHBA-2019:0959 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:0746 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0766 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0985 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-3878 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1691126 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3878 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/Uninett/mod_auth_mellon/pull/196 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNW5YMC5TLWVWNJEY6AIWNSNPRAMWPQJ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X7NLAU7KROWNTHAYSA2S67X347F42L2I/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-3878
- https://usn.ubuntu.com/3924-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3878
Change history (0)
No recorded changes yet.