When contributed modules such as Workflow NG terminate the current request during a login event, user module was not able to regenerate the user’s session. This may lead to a session fixation attack, when a malicious user was able to control another users’ initial session ID. As the session was not regenerated, the malicious user may use the ‘fixed’ session ID after the victim authenticates and would have the same access. This issue affects both Drupal 5 and Drupal 6.
Part of security release SA-2008-044
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2