First published: Mon Nov 24 2014(Updated: )
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >=6.0<6.34 | |
Drupal | >=7.0<7.34 | |
Debian Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9015 is considered a critical vulnerability due to its potential for session hijacking.
To fix CVE-2014-9015, upgrade to Drupal 6.34 or 7.34 or later versions.
CVE-2014-9015 affects Drupal versions prior to 6.34 and 7.34.
CVE-2014-9015 allows remote attackers to hijack user sessions via crafted requests.
Using older versions of Drupal that are affected by CVE-2014-9015 poses significant security risks.