CVE-2010-3685: Medium severity Drupal Drupal vulnerability
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.responsenonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3685?
CVE-2010-3685 is classified as a high-severity vulnerability, allowing attackers to bypass authentication.
How do I fix CVE-2010-3685?
To fix CVE-2010-3685, update the OpenID module in Drupal to version 5.x-1.4 or 6.18 or later.
What impact does CVE-2010-3685 have on my Drupal site?
CVE-2010-3685 can allow unauthorized access to user accounts by exploiting the OpenID authentication process.
Which versions of Drupal are affected by CVE-2010-3685?
CVE-2010-3685 affects Drupal 6.x versions before 6.18 and OpenID module 5.x versions before 5.x-1.4.
Is there a patch available for CVE-2010-3685?
Yes, patches have been released in Drupal updates for CVE-2010-3685.