PT-2010-5000 · Drupal · Drupal Openid Module

Published

2010-09-29

·

Updated

2010-09-30

·

CVE-2010-3686

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal OpenID module versions prior to 6.18 Drupal OpenID module 5.x versions prior to 5.x-1.4
Description The issue concerns the OpenID module in Drupal, which fails to adhere to the OpenID 2.0 protocol. Specifically, it does not ensure that fields are signed, allowing remote attackers to bypass authentication. This can be achieved by leveraging an assertion from an OpenID provider.
Recommendations For Drupal 6.x, update to version 6.18 or later to resolve the issue. For Drupal 5.x, update the OpenID module to version 5.x-1.4 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3686
DSA-2113-1

Affected Products

Drupal Openid Module