Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3686
HistorySep 29, 2010 - 12:00 a.m.

CVE-2010-3686

2010-09-2900:00:00
ubuntu.com
ubuntu.com
9

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.9%

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x
before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring
that fields are signed, which allows remote attackers to bypass
authentication by leveraging an assertion from an OpenID provider.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchdrupal5< 5.7-1ubuntu1.3UNKNOWN
ubuntu9.10noarchdrupal5< 5.18-1.1ubuntu2.2UNKNOWN
ubuntu10.04noarchdrupal6< 6.16-1ubuntu0.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

75.9%