The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://drupal.org/node/1632702 | patch |
http://drupal.org/node/1632734 | patch vendor advisory |
http://drupal.org/node/1632704 | patch |
http://osvdb.org/82957 | vdb entry |