Bug#991730: libapache2-mod-auth-mellon: CVE-2021-3639: open redirect vulnerability

2021-08-06 Thread Thijs Kinkhorst
Hi Salvatore, > CVE-2021-3639[0]: > | Prevent redirect to URLs that begin with '///' I have a fixed package prepared and tested for sid but can only upload this next week when I return from holiday. I consider this (open redirect in general) a minor issue so I don't think it's needed to

Bug#991730: libapache2-mod-auth-mellon: CVE-2021-3639: open redirect vulnerability

2021-07-31 Thread Salvatore Bonaccorso
Source: libapache2-mod-auth-mellon Version: 0.17.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for libapache2-mod-auth-mellon. CVE-2021-3639[0]: | Prevent redirect to URLs that begin with