The OpenID module didn’t implement all the required verifications from the OpenID 2.0 protocol and was vulnerable to a number of attacks.

Specifically:

– OpenID should verify that a “openid.response_nonce” had not already been used for an assertion by the OpenID provider

– OpenID should verify the value of openid.return_to as obtained from the OpenID provider

– OpenID must verify that all fields that were required to be signed were signed

These specification violations allowed malicious sites to harvest positive assertions from OpenID providers and used them on sites using the OpenID module to obtain access to preexisting accounts bound to the harvested OpenIDs. Intercepted assertions from OpenID providers could also be replayed and used to obtain access to user accounts bound to the intercepted OpenIDs.

Part of security release SA-CORE-2010-002

This vulnerability affects the following application versions:

  • Drupal 6.0
  • Drupal 6.1
  • Drupal 6.2
  • Drupal 6.3
  • Drupal 6.4
  • Drupal 6.5
  • Drupal 6.6
  • Drupal 6.7
  • Drupal 6.8
  • Drupal 6.9
  • Drupal 6.10
  • Drupal 6.11
  • Drupal 6.12
  • Drupal 6.13
  • Drupal 6.14
  • Drupal 6.15
  • Drupal 6.16
  • Drupal 6.17

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *