CVE-2010-2473: Input Validation
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2473?
The severity of CVE-2010-2473 is medium with a severity value of 6.5.
How does CVE-2010-2473 affect Drupal?
CVE-2010-2473 affects Drupal versions 6.x before 6.16 and 5.x before 5.22 by not properly blocking users under certain circumstances.
How can a user with an open session maintain their session on a Drupal site despite being blocked?
A user with an open session can maintain their session on a Drupal site despite being blocked due to the vulnerability of CVE-2010-2473.
Is there a fix for CVE-2010-2473?
Yes, there is a fix available for CVE-2010-2473. It is recommended to update Drupal to version 6.16 or 5.22, depending on the affected version.
Where can I find more information about CVE-2010-2473?
You can find more information about CVE-2010-2473 on the Drupal website, Openwall OSS Security mailing list, and the Debian Security Tracker.