Drupal Token Authentication Module Access Bypass Vulnerability
BID:53840
Info
Drupal Token Authentication Module Access Bypass Vulnerability
| Bugtraq ID: | 53840 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-2720 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2012 12:00AM |
| Updated: | Aug 07 2012 08:52PM |
| Credit: | John Morahan |
| Vulnerable: |
Drupal Token Authentication 6.X-1.6 Drupal Token Authentication 6.x-1.1 |
| Not Vulnerable: |
Drupal Token Authentication 6.X-1.7 |
Discussion
Drupal Token Authentication Module Access Bypass Vulnerability
Token Authentication module for Drupal is prone to an access bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to sensitive areas of application, thus perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Token Authentication 6.x-1.7 are vulnerable.
Token Authentication module for Drupal is prone to an access bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to sensitive areas of application, thus perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Token Authentication 6.x-1.7 are vulnerable.
Exploit / POC
Drupal Token Authentication Module Access Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Drupal Token Authentication Module Access Bypass Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Drupal Token Authentication Module Access Bypass Vulnerability
References:
References:
- Contact Forms Homepage (Drupal)
- SA-CONTRIB-2012-091 - Token Authentication - Access bypass (Adam Ross)