Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4p2-3684-fq47

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

EPSS

Процентиль: 72%
0.0073
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

nvd
больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

debian
больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

EPSS

Процентиль: 72%
0.0073
Низкий

Дефекты

CWE-287