The core OpenID module did not correctly implement Form API for the form that allowed one to link user accounts with OpenID identifiers. A malicious user was therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities could then be used to gain access to the affected accounts.
Part of security release SA-CORE-2009-008
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8
- Drupal 6.9
- Drupal 6.10
- Drupal 6.11
- Drupal 6.12
- Drupal 6.13