The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://drupal.org/node/880480 | patch vendor advisory |
http://www.debian.org/security/2010/dsa-2113 | vendor advisory |
http://marc.info/?l=oss-security&m=128440896914512&w=2 | mailing list |
http://www.securityfocus.com/bid/42388 | vdb entry |
http://drupal.org/node/880476 | patch vendor advisory |
http://marc.info/?l=oss-security&m=128418560705305&w=2 | mailing list |