Drupal CAS Server Module Security Bypass Vulnerability
BID:66625
Info
Drupal CAS Server Module Security Bypass Vulnerability
| Bugtraq ID: | 66625 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2014 12:00AM |
| Updated: | Apr 02 2014 12:00AM |
| Credit: | Eric Searcy |
| Vulnerable: |
Drupal CAS Server 6.X-2.1 |
| Not Vulnerable: |
Drupal CAS Server 7.x-1.3 Drupal CAS Server 6.X-3.3 |
Discussion
Drupal CAS Server Module Security Bypass Vulnerability
Drupal CAS Server module is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to re-initialize user sessions which may lead in further attacks.
Drupal CAS Server module is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to re-initialize user sessions which may lead in further attacks.
Solution / Fix
Drupal CAS Server Module Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Drupal CAS Server Module Security Bypass Vulnerability
References:
References:
- Drupal CAS Server Homepage (Drupal)
- SA-CONTRIB-2014-035 - CAS Server - Access Bypass (Drupal)