PT-2010-4538 · Drupal · Drupal Openid Module

Steffen Joeris

·

Published

2010-09-29

·

Updated

2010-09-30

·

CVE-2010-3091

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions prior to 6.18 Drupal OpenID module 5.x versions prior to 5.x-1.4
Description The issue concerns the OpenID module in Drupal, which fails to verify the openid.return to value as per the OpenID 2.0 protocol. This allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Recommendations For Drupal 6.x, update to version 6.18 or later. For Drupal 5.x, update to OpenID module version 5.x-1.4 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3091
DSA-2113-1

Affected Products

Drupal Openid Module