PT-2010-4999 · Drupal · Drupal Openid Module

Steffen Joeris

·

Published

2010-09-29

·

Updated

2010-09-30

·

CVE-2010-3685

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions prior to 6.18 Drupal OpenID module 5.x versions prior to 5.x-1.4
Description The issue concerns the OpenID module in Drupal, which fails to adhere to the OpenID 2.0 protocol. Specifically, it does not check for the reuse of openid.response nonce values. This oversight allows remote attackers to bypass authentication by utilizing an assertion from an OpenID provider.
Recommendations For Drupal 6.x, update to version 6.18 or later. For Drupal 5.x, update to OpenID module version 5.x-1.4 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3685
DSA-2113-1

Affected Products

Drupal Openid Module