SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion…

MEDIUM 5.0EPSS 2.37%

Does this matter?

Lower severity and a low EPSS score (2.37%). Track it; it rarely justifies an emergency change on its own.

Description

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.37% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
drupal/drupal · peter wolanin/openid
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.