CVE-2010-3686
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion…
Does this matter?
Lower severity and a low EPSS score (2.37%). Track it; it rarely justifies an emergency change on its own.
Description
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.37% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- drupal/drupal · peter wolanin/openid
- Source
- cve@mitre.org
References
- http://drupal.org/node/880476Patch, Vendor Advisory
- http://drupal.org/node/880480Patch, Vendor Advisory
- http://marc.info/?l=oss-security&m=128418560705305&w=2
- http://marc.info/?l=oss-security&m=128440896914512&w=2
- http://www.debian.org/security/2010/dsa-2113
- http://www.securityfocus.com/bid/42388
- http://drupal.org/node/880476Patch, Vendor Advisory
- http://drupal.org/node/880480Patch, Vendor Advisory
- http://marc.info/?l=oss-security&m=128418560705305&w=2
- http://marc.info/?l=oss-security&m=128440896914512&w=2
- http://www.debian.org/security/2010/dsa-2113
- http://www.securityfocus.com/bid/42388
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.