Drupal Core Access Bypass and Open Redirection Vulnerabilities
BID:73219
CVE-2015-2749 | CVE-2015-2750 |Info
Drupal Core Access Bypass and Open Redirection Vulnerabilities
| Bugtraq ID: | 73219 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-2559 CVE-2015-2749 CVE-2015-2750 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2015 12:00AM |
| Updated: | Jul 15 2015 12:16AM |
| Credit: | Daniël Smidt, Hunter Fox of the Drupal Security Team, Vlad Stratulat, Michael Smith, and Dave Reid of the Drupal Security Team. |
| Vulnerable: |
Drupal Drupal 7.6 Drupal Drupal 7.5 Drupal Drupal 7.4 Drupal Drupal 7.3 Drupal Drupal 7.2 Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 Drupal Drupal 7.1 Drupal Drupal 7.0 Drupal Drupal 6.9 Drupal Drupal 6.8 Drupal Drupal 6.7 Drupal Drupal 6.6 Drupal Drupal 6.5 Drupal Drupal 6.4 Drupal Drupal 6.3 Drupal Drupal 6.23 Drupal Drupal 6.22 Drupal Drupal 6.2 Drupal Drupal 6.18 Drupal Drupal 6.17 Drupal Drupal 6.16 Drupal Drupal 6.15 Drupal Drupal 6.14 Drupal Drupal 6.13 Drupal Drupal 6.12 Drupal Drupal 6.11 Drupal Drupal 6.10 Drupal Drupal 6.1 Drupal Drupal 6.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Drupal Core Access Bypass and Open Redirection Vulnerabilities
Drupal is prone to an access-bypass vulnerability and an open-redirection vulnerability.
An attacker can leverage these issues to bypass certain security restrictions and gain unauthorized access and by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following versions are vulnerable:
Drupal core 6.x versions prior to 6.35
Drupal core 7.x versions prior to 7.35
Drupal is prone to an access-bypass vulnerability and an open-redirection vulnerability.
An attacker can leverage these issues to bypass certain security restrictions and gain unauthorized access and by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following versions are vulnerable:
Drupal core 6.x versions prior to 6.35
Drupal core 7.x versions prior to 7.35
Exploit / POC
Drupal Core Access Bypass and Open Redirection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
Drupal Core Access Bypass and Open Redirection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.