PT-2008-2196 · Drupal · Drupal Openid Module
Published
2008-02-05
·
Updated
2011-03-08
·
CVE-2008-0570
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal OpenID module versions 5.x-1.0 and earlier
Description
The issue arises from the improper verification of the claimed id returned by an OpenID provider, allowing remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
Recommendations
For versions 5.x-1.0 and earlier, update to a version that properly verifies the claimed id to prevent spoofing of OpenID authentication.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal Openid Module