Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prjg-45g9-9qgc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

EPSS

Процентиль: 75%
0.00931
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

nvd
почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

debian
почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

EPSS

Процентиль: 75%
0.00931
Низкий

Дефекты

CWE-287