PT-2010-4999 · Drupal · Drupal Openid Module

Steffen Joeris

·

Publicado

2010-09-29

·

Atualizado

2010-09-30

·

CVE-2010-3685

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions prior to 6.18 Drupal OpenID module 5.x versions prior to 5.x-1.4
Description The issue concerns the OpenID module in Drupal, which fails to adhere to the OpenID 2.0 protocol. Specifically, it does not check for the reuse of openid.response nonce values. This oversight allows remote attackers to bypass authentication by utilizing an assertion from an OpenID provider.
Recommendations For Drupal 6.x, update to version 6.18 or later. For Drupal 5.x, update to OpenID module version 5.x-1.4 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3685
DSA-2113-1

Produtos afetados

Drupal Openid Module