The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161265.html | vendor advisory |
http://www.securityfocus.com/bid/75294 | vdb entry |
http://www.debian.org/security/2015/dsa-3291 | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html | vendor advisory |
https://www.drupal.org/SA-CORE-2015-002 | patch vendor advisory |