PT-2008-2196 · Drupal · Drupal Openid Module
Publicado
2008-02-05
·
Atualizado
2011-03-08
·
CVE-2008-0570
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal OpenID module versions 5.x-1.0 and earlier
Description
The issue arises from the improper verification of the claimed id returned by an OpenID provider, allowing remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
Recommendations
For versions 5.x-1.0 and earlier, update to a version that properly verifies the claimed id to prevent spoofing of OpenID authentication.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal Openid Module