PT-2008-2196 · Drupal · Drupal Openid Module

Publicado

2008-02-05

·

Atualizado

2011-03-08

·

CVE-2008-0570

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions 5.x-1.0 and earlier
Description The issue arises from the improper verification of the claimed id returned by an OpenID provider, allowing remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
Recommendations For versions 5.x-1.0 and earlier, update to a version that properly verifies the claimed id to prevent spoofing of OpenID authentication.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0570

Produtos afetados

Drupal Openid Module