Drupal Shared Sign On Module Cross-Site Request Forgery and Session Fixation Vulnerabilities
BID:36563
Info
Drupal Shared Sign On Module Cross-Site Request Forgery and Session Fixation Vulnerabilities
| Bugtraq ID: | 36563 |
| Class: | Unknown |
| CVE: |
CVE-2009-3656 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Jose A. Reyero and Steven Wittens |
| Vulnerable: |
Drupal Shared Sign On 0 |
| Not Vulnerable: | |
Discussion
Drupal Shared Sign On Module Cross-Site Request Forgery and Session Fixation Vulnerabilities
The Shared Sign On module for Drupal is prone to a cross-site request-forgery vulnerability and a session-fixation vulnerability.
Attackers may exploit these issues to perform unauthorized actions, hijack arbitrary sessions, compromise the affected application, and modify administration settings. Other attacks are also possible.
The Shared Sign On module for Drupal is prone to a cross-site request-forgery vulnerability and a session-fixation vulnerability.
Attackers may exploit these issues to perform unauthorized actions, hijack arbitrary sessions, compromise the affected application, and modify administration settings. Other attacks are also possible.
Exploit / POC
Drupal Shared Sign On Module Cross-Site Request Forgery and Session Fixation Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
To exploit these issues, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
Solution / Fix
Drupal Shared Sign On Module Cross-Site Request Forgery and Session Fixation Vulnerabilities
Solution:
Drupal has discontinued support for the vulnerable module and recommends that users migrate to the Single Sign On module. Please see the references for more information.
Solution:
Drupal has discontinued support for the vulnerable module and recommends that users migrate to the Single Sign On module. Please see the references for more information.
References
Drupal Shared Sign On Module Cross-Site Request Forgery and Session Fixation Vulnerabilities
References:
References: