VulnerabilityModified
CVE-2012-0825
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
MEDIUM 6.8EPSS 1.98%
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- drupal/drupal
- Source
- secalert@redhat.com
References
- http://openid.net/2011/05/05/attribute-exchange-security-alert/
- http://www.debian.org/security/2013/dsa-2776
- https://drupal.org/node/1425084Vendor Advisory
- http://openid.net/2011/05/05/attribute-exchange-security-alert/
- http://www.debian.org/security/2013/dsa-2776
- https://drupal.org/node/1425084Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.