Drupal Secure Cookie Data Module Hardcoded Cryptographic Key Vulnerability
BID:65095
Info
Drupal Secure Cookie Data Module Hardcoded Cryptographic Key Vulnerability
| Bugtraq ID: | 65095 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2014 12:00AM |
| Updated: | Jan 22 2014 12:00AM |
| Credit: | Jonathan Kuma |
| Vulnerable: |
Drupal Secure Cookie Data 7.x-2.0 |
| Not Vulnerable: |
Drupal Secure Cookie Data 7.x-2.1 |
Discussion
Drupal Secure Cookie Data Module Hardcoded Cryptographic Key Vulnerability
The Secure Cookie Data module for Drupal is prone to a vulnerability caused by hard-coded cryptographic key.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
Secure Cookie Data 7.x-2.x versions prior to 7.x-2.1 are vulnerable.
The Secure Cookie Data module for Drupal is prone to a vulnerability caused by hard-coded cryptographic key.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
Secure Cookie Data 7.x-2.x versions prior to 7.x-2.1 are vulnerable.
Exploit / POC
Drupal Secure Cookie Data Module Hardcoded Cryptographic Key Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
Drupal Secure Cookie Data Module Hardcoded Cryptographic Key Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Drupal Secure Cookie Data Module Hardcoded Cryptographic Key Vulnerability
References:
References:
- Drupal Homepage (Drupal)
- SA-CONTRIB-2014-004 - Secure Cookie Data - Faulty Hashing (Drupal)