PT-2010-5000 · Drupal · Drupal Openid Module

Publicado

2010-09-29

·

Atualizado

2010-09-30

·

CVE-2010-3686

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions prior to 6.18 Drupal OpenID module 5.x versions prior to 5.x-1.4
Description The issue concerns the OpenID module in Drupal, which fails to adhere to the OpenID 2.0 protocol. Specifically, it does not ensure that fields are signed, allowing remote attackers to bypass authentication. This can be achieved by leveraging an assertion from an OpenID provider.
Recommendations For Drupal 6.x, update to version 6.18 or later to resolve the issue. For Drupal 5.x, update the OpenID module to version 5.x-1.4 or later to resolve the issue.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3686
DSA-2113-1

Produtos afetados

Drupal Openid Module