CVE-2015-3234: Input Validation
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3234?
CVE-2015-3234 is classified as a critical vulnerability due to its ability to allow remote attackers to log into other users' accounts.
How do I fix CVE-2015-3234?
To fix CVE-2015-3234, update your Drupal installation to versions 6.36 or 7.38 or later.
What versions of Drupal are affected by CVE-2015-3234?
CVE-2015-3234 affects Drupal versions 6.x prior to 6.36 and 7.x prior to 7.38.
What are the potential impacts of CVE-2015-3234?
The potential impact of CVE-2015-3234 includes unauthorized access to user accounts and sensitive information.
Is there a workaround for CVE-2015-3234?
No official workarounds are available for CVE-2015-3234, so updating to the latest version is the recommended approach.