Drupal Core CVE-2014-9015 Session Hijacking Vulnerability
BID:71195
Info
Drupal Core CVE-2014-9015 Session Hijacking Vulnerability
| Bugtraq ID: | 71195 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9015 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2014 12:00AM |
| Updated: | Apr 13 2015 09:41PM |
| Credit: | Aaron Averill |
| Vulnerable: |
Drupal Drupal 7.3 Drupal Drupal 7.2 Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 Drupal Drupal 7.1 Drupal Drupal 7.0 Dev Drupal Drupal 7.0 Alpha7 Drupal Drupal 7.0 Alpha6 Drupal Drupal 7.0 Alpha5 Drupal Drupal 7.0 Alpha4 Drupal Drupal 7.0 Alpha3 Drupal Drupal 7.0 Alpha2 Drupal Drupal 7.0 Alpha1 Drupal Drupal 7.0 Drupal Drupal 6.3 Drupal Drupal 6.23 Drupal Drupal 6.22 Drupal Drupal 6.2 Drupal Drupal 6.18 Drupal Drupal 6.17 Drupal Drupal 6.16 Drupal Drupal 6.15 Drupal Drupal 6.14 Drupal Drupal 6.13 Drupal Drupal 6.12 Drupal Drupal 6.11 Drupal Drupal 6.10 Drupal Drupal 6.1 Drupal Drupal 6.0 Rc4 Drupal Drupal 6.0 Rc3 Drupal Drupal 6.0 Rc2 Drupal Drupal 6.0 Rc1 Drupal Drupal 6.0 Dev Drupal Drupal 6.0 Beta4 Drupal Drupal 6.0 Beta3 Drupal Drupal 6.0 Beta2 Drupal Drupal 6.0 Beta1 Drupal Drupal 6.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Drupal Core CVE-2014-9015 Session Hijacking Vulnerability
Drupal Core is prone to a session-hijacking vulnerability.
Successful exploits may allow an attacker to gain unauthorized access to the affected application.
The following versions are vulnerable:
Drupal 6.x versions prior to 6.34.
Drupal 7.x versions prior to 7.34.
Note: The issue described by CVE-2014-9016 has been moved to BID 71202 (Drupal Core CVE-2014-9016 Denial of Service Vulnerability) for better documentation.
Drupal Core is prone to a session-hijacking vulnerability.
Successful exploits may allow an attacker to gain unauthorized access to the affected application.
The following versions are vulnerable:
Drupal 6.x versions prior to 6.34.
Drupal 7.x versions prior to 7.34.
Note: The issue described by CVE-2014-9016 has been moved to BID 71202 (Drupal Core CVE-2014-9016 Denial of Service Vulnerability) for better documentation.
Solution / Fix
Drupal Core CVE-2014-9015 Session Hijacking Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.