Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-2685

Опубликовано: 04 сент. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

РелизСтатусПримечание
devel

DNE

lucid

ignored

end of life
precise

DNE

quantal

DNE

saucy

DNE

upstream

released

1.12.4

Показывать по

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

debian
больше 11 лет назад

The GenericConsumer class in the Consumer component in ZendOpenId befo ...

github
больше 3 лет назад

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

7.5 High

CVSS2