Session hijacking in Drupal - CVE-2014-9015
Published: September 14, 2016
Vulnerability identifier: #VU443
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9015
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allow a remore user to hijack a valid user's session.
The weakness exists due to specially crafted requests that gives a user access to another user's session and allows attacker to steal a random session.
Successful exploitation of this vulnerability may result in hijacking of the target user's session.
The weakness exists due to specially crafted requests that gives a user access to another user's session and allows attacker to steal a random session.
Successful exploitation of this vulnerability may result in hijacking of the target user's session.
Affected software
Drupal
Arch Linux
Debian Linux
Fedora
drupal6
drupal7
Arch Linux
Debian Linux
Fedora
drupal6
drupal7
How to mitigate CVE-2014-9015
Update 6.x to 6.34.
https://www.drupal.org/drupal-6.34-release-notes
Update 7.x to 7.34.
https://www.drupal.org/drupal-7.34-release-notes
https://www.drupal.org/drupal-6.34-release-notes
Update 7.x to 7.34.
https://www.drupal.org/drupal-7.34-release-notes
drupal6 - addressed in versions 6.34-1.el5, 6.34-1.el6, 6.34-1.fc21
drupal7 - addressed in versions 7.34-1.el5, 7.34-1.el6, 7.34-1.el7, 7.34-1.fc21
drupal7 - addressed in versions 7.34-1.el5, 7.34-1.el6, 7.34-1.el7, 7.34-1.fc21