First published: Thu Nov 07 2019(Updated: )
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=6.0<6.16 | |
Drupal Drupal | >=5.0<5.22 | |
debian/drupal6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-2473 is medium with a severity value of 6.5.
CVE-2010-2473 affects Drupal versions 6.x before 6.16 and 5.x before 5.22 by not properly blocking users under certain circumstances.
A user with an open session can maintain their session on a Drupal site despite being blocked due to the vulnerability of CVE-2010-2473.
Yes, there is a fix available for CVE-2010-2473. It is recommended to update Drupal to version 6.16 or 5.22, depending on the affected version.
You can find more information about CVE-2010-2473 on the Drupal website, Openwall OSS Security mailing list, and the Debian Security Tracker.