CVE-2016-3164: High severity drupal vulnerability
Published Feb 15, 2016
·Updated
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
Affected Software
151 affected componentsFixes available
composer/drupal/core>=8.0, <8.0.4
composer/drupal/drupal>=8.0, <8.0.4
composer/drupal/core>=6.0<6.38
6.38
composer/drupal/core>=7.0<7.43
7.43
composer/drupal/core>=8.0<8.0.4
8.0.4
composer/drupal/drupal>=8.0<8.0.4
8.0.4
composer/drupal/drupal>=7.0<7.43
7.43
composer/drupal/drupal>=6.0<6.38
6.38
Drupal Drupal=6.0
Drupal Drupal=6.0-beta1
Drupal Drupal=6.0-beta2
Drupal Drupal=6.0-beta3
Drupal Drupal=6.0-beta4
Drupal Drupal=6.0-dev
Drupal Drupal=6.0-rc1
Drupal Drupal=6.0-rc2
Drupal Drupal=6.0-rc3
Drupal Drupal=6.0-rc4
Drupal Drupal=6.1
Drupal Drupal=6.2
Drupal Drupal=6.3
Drupal Drupal=6.4
Drupal Drupal=6.5
Drupal Drupal=6.6
Drupal Drupal=6.7
Drupal Drupal=6.8
Drupal Drupal=6.9
Drupal Drupal=6.10
Drupal Drupal=6.11
Drupal Drupal=6.12
Drupal Drupal=6.13
Drupal Drupal=6.14
Drupal Drupal=6.15
Drupal Drupal=6.16
Drupal Drupal=6.17
Drupal Drupal=6.18
Drupal Drupal=6.19
Drupal Drupal=6.20
Drupal Drupal=6.21
Drupal Drupal=6.22
Drupal Drupal=6.23
Drupal Drupal=6.24
Drupal Drupal=6.25
Drupal Drupal=6.26
Drupal Drupal=6.27
Drupal Drupal=6.28
Drupal Drupal=6.29
Drupal Drupal=6.30
Drupal Drupal=6.31
Drupal Drupal=6.32
Drupal Drupal=6.33
Drupal Drupal=6.34
Drupal Drupal=6.35
Drupal Drupal=6.36
Drupal Drupal=6.37
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.14
Drupal Drupal=7.15
Drupal Drupal=7.16
Drupal Drupal=7.17
Drupal Drupal=7.18
Drupal Drupal=7.19
Drupal Drupal=7.20
Drupal Drupal=7.21
Drupal Drupal=7.22
Drupal Drupal=7.23
Drupal Drupal=7.24
Drupal Drupal=7.25
Drupal Drupal=7.26
Drupal Drupal=7.27
Drupal Drupal=7.28
Drupal Drupal=7.29
Drupal Drupal=7.30
Drupal Drupal=7.31
Drupal Drupal=7.32
Drupal Drupal=7.33
Drupal Drupal=7.34
Drupal Drupal=7.35
Drupal Drupal=7.36
Drupal Drupal=7.37
Drupal Drupal=7.38
Drupal Drupal=7.40
Drupal Drupal=7.41
Drupal Drupal=7.42
Drupal Drupal=7.x-dev
Drupal Drupal=8.0.0
Drupal Drupal=8.0.0-alpha10
Drupal Drupal=8.0.0-alpha11
Drupal Drupal=8.0.0-alpha12
Drupal Drupal=8.0.0-alpha13
Drupal Drupal=8.0.0-alpha14
Drupal Drupal=8.0.0-alpha15
Drupal Drupal=8.0.0-alpha2
Drupal Drupal=8.0.0-alpha3
Drupal Drupal=8.0.0-alpha4
Drupal Drupal=8.0.0-alpha5
Drupal Drupal=8.0.0-alpha6
Drupal Drupal=8.0.0-alpha7
Drupal Drupal=8.0.0-alpha8
Drupal Drupal=8.0.0-alpha9
Drupal Drupal=8.0.0-beta1
Drupal Drupal=8.0.0-beta10
Drupal Drupal=8.0.0-beta11
Drupal Drupal=8.0.0-beta12
Drupal Drupal=8.0.0-beta13
Drupal Drupal=8.0.0-beta14
Drupal Drupal=8.0.0-beta15
Drupal Drupal=8.0.0-beta16
Drupal Drupal=8.0.0-beta2
Drupal Drupal=8.0.0-beta3
Drupal Drupal=8.0.0-beta4
Drupal Drupal=8.0.0-beta6
Drupal Drupal=8.0.0-beta7
Drupal Drupal=8.0.0-beta9
Drupal Drupal=8.0.0-rc1
Drupal Drupal=8.0.0-rc2
Drupal Drupal=8.0.0-rc3
Drupal Drupal=8.0.0-rc4
Drupal Drupal=8.0.1
Drupal Drupal=8.0.2
Drupal Drupal=8.0.3
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Feb 15, 2016
Advisory Published
06:57 PM
Apr 12, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3164?
CVE-2016-3164 has a medium severity level due to its potential for exploitation through open redirect attacks.
2
How do I fix CVE-2016-3164?
To mitigate CVE-2016-3164, update your Drupal installation to version 6.38, 7.43, or 8.0.4 or later.
3
Which Drupal versions are affected by CVE-2016-3164?
CVE-2016-3164 affects Drupal versions prior to 6.38, 7.43, and 8.0.4.
4
Is CVE-2016-3164 easy to exploit?
Yes, exploiting CVE-2016-3164 is relatively straightforward as it involves open redirect functionality.
5
What types of attacks can CVE-2016-3164 enable?
CVE-2016-3164 can allow remote attackers to conduct open redirect attacks, potentially leading to phishing or redirection to malicious sites.