PT-2008-2196 · Drupal · Drupal Openid Module

Published

2008-02-05

·

Updated

2011-03-08

·

CVE-2008-0570

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions 5.x-1.0 and earlier
Description The issue arises from the improper verification of the claimed id returned by an OpenID provider, allowing remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
Recommendations For versions 5.x-1.0 and earlier, update to a version that properly verifies the claimed id to prevent spoofing of OpenID authentication.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0570

Affected Products

Drupal Openid Module