CVE-2010-3686: Medium severity Drupal Drupal vulnerability
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3686?
CVE-2010-3686 is classified as a moderate severity vulnerability that allows unauthorized access through the manipulation of OpenID assertions.
How do I fix CVE-2010-3686?
To fix CVE-2010-3686, update to Drupal 6.18 or later for Drupal 6.x or 5.x-1.4 or later for the OpenID module.
What versions of Drupal are affected by CVE-2010-3686?
CVE-2010-3686 affects Drupal versions 6.0 through 6.17 and OpenID module versions prior to 5.x-1.4.
Is there a workaround for CVE-2010-3686?
No official workaround exists for CVE-2010-3686, and upgrading to the latest version is the recommended approach.
What types of attacks can exploit CVE-2010-3686?
CVE-2010-3686 can be exploited by attackers to bypass authentication and gain unauthorized access to user accounts via manipulated OpenID assertions.