The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://drupal.org/node/880476 - Patch, Vendor Advisory | |
References | () http://drupal.org/node/880480 - Patch, Vendor Advisory | |
References | () http://marc.info/?l=oss-security&m=128418560705305&w=2 - | |
References | () http://marc.info/?l=oss-security&m=128440896914512&w=2 - | |
References | () http://www.debian.org/security/2010/dsa-2113 - | |
References | () http://www.securityfocus.com/bid/42388 - |
Information
Published : 2010-09-29 17:00
Updated : 2024-11-21 01:19
NVD link : CVE-2010-3686
Mitre link : CVE-2010-3686
CVE.ORG link : CVE-2010-3686
JSON object : View
Products Affected
drupal
- drupal
peter_wolanin
- openid
CWE
CWE-287
Improper Authentication