USN-4291-1: mod-auth-mellon vulnerability
24 February 2020
libapache2-mod-auth-mellon could be made to redirect users to malicious sites.
Releases
Packages
- libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache
Details
It was discovered that mod_auth_mellon incorrectly handled certain
requests. An attacker could possibly use this issue to redirect a user to a
malicious URL.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 19.10
Ubuntu 18.04
In general, a standard system update will make all the necessary changes.