The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2010-09-29 17:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-3685
Mitre link : CVE-2010-3685
CVE.ORG link : CVE-2010-3685
JSON object : View
Products Affected
peter_wolanin
- openid
drupal
- drupal
CWE
CWE-287
Improper Authentication