The core OpenID module did not correctly implement Form API for the form that allowed one to link user accounts with OpenID identifiers. A malicious user was therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities could then be used to gain access to the affected accounts.

Part of security release SA-CORE-2009-008

This vulnerability affects the following application versions:

  • Drupal 6.0
  • Drupal 6.1
  • Drupal 6.2
  • Drupal 6.3
  • Drupal 6.4
  • Drupal 6.5
  • Drupal 6.6
  • Drupal 6.7
  • Drupal 6.8
  • Drupal 6.9
  • Drupal 6.10
  • Drupal 6.11
  • Drupal 6.12
  • Drupal 6.13

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *