OSVDB ID: 82466

Title: BrowserID Module for Drupal BrowserID / Mozilla Persona audience Identifier Authentication Login Spoofing

Info

Disclosure

May 23, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

May 23, 2012

Description

BrowserID Module for Drupal contains a flaw that is triggered when handling the authentication of a BrowserID or Mozilla persona "audience" identifier. This may allow an attacker to spoof the login by modifying the "audience" identifier after visiting malicious website.

Classification

Location: Remote / Network Access
Attack Type: Authentication Management
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 7.x-1.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Isaac Sukin

BrowserID Module for Drupal

7.x-1.2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/82466