Total vulnerabilities in the database
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
Software | From | Fixed in |
---|---|---|
mod_auth_mellon_project / mod_auth_mellon | - | 0.14.2.x |
oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 18.10 | 18.10.x |