Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
BID:27542
Info
Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
| Bugtraq ID: | 27542 |
| Class: | Design Error |
| CVE: |
CVE-2008-0570 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2008 12:00AM |
| Updated: | Apr 16 2015 06:06PM |
| Credit: | Johnny Bufu discovered this issue. |
| Vulnerable: |
OpenID OpenID module 5.x-1.0 |
| Not Vulnerable: |
OpenID OpenID module 5.x-1.1 |
Discussion
Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
The OpenID module for Drupal is prone to a vulnerability that allows attackers to set up malicious OpenID Providers to spoof a legitimate OpenID Authority.
Attackers can exploit this issue to gain unauthorized access to websites that rely on OpenID authentication.
Versions prior to OpenID 5.x-1.1 are vulnerable.
The OpenID module for Drupal is prone to a vulnerability that allows attackers to set up malicious OpenID Providers to spoof a legitimate OpenID Authority.
Attackers can exploit this issue to gain unauthorized access to websites that rely on OpenID authentication.
Versions prior to OpenID 5.x-1.1 are vulnerable.
Exploit / POC
Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
Solution:
The vendor released OpenID 5.x-1.1 to address this issue. Please see the references for more information.
OpenID OpenID module 5.x-1.0
Solution:
The vendor released OpenID 5.x-1.1 to address this issue. Please see the references for more information.
OpenID OpenID module 5.x-1.0
-
OpenID openid-5.x-1.1.tar.gz
http://ftp.drupal.org/files/projects/openid-5.x-1.1.tar.gz
References
Drupal OpenID Module 'claimed_id' Provider Spoofing Vulnerability
References:
References:
- openid 5.x-1.1 (Drupal)
- Vendor Homepage (OpenID)
- SA-2008-016 - OpenID - Incorrect claimed_id returned for OpenID 2.0 (Drupal)