Lucene search

K
cvelistMitreCVELIST:CVE-2010-3686
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2010-3686

2022-10-0316:20:58
mitre
www.cve.org
5
drupal
openid
module
security
vulnerability
bypass
authentication

AI Score

6.7

Confidence

High

EPSS

0.005

Percentile

75.9%

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

AI Score

6.7

Confidence

High

EPSS

0.005

Percentile

75.9%

Related for CVELIST:CVE-2010-3686