CVE-2014-9015: Medium severity drupal vulnerability
Published Nov 24, 2014
·Updated
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
Affected Software
3 affected components
Drupal Drupal>=6.0<6.34
Drupal Drupal>=7.0<7.34
Debian Debian Linux=7.0
Event History
Nov 24, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9015?
CVE-2014-9015 is considered a critical vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2014-9015?
To fix CVE-2014-9015, upgrade to Drupal 6.34 or 7.34 or later versions.
3
Who is affected by CVE-2014-9015?
CVE-2014-9015 affects Drupal versions prior to 6.34 and 7.34.
4
What kind of attacks are possible with CVE-2014-9015?
CVE-2014-9015 allows remote attackers to hijack user sessions via crafted requests.
5
Is it safe to use older versions of Drupal after CVE-2014-9015?
Using older versions of Drupal that are affected by CVE-2014-9015 poses significant security risks.