CVE-2014-9015
published 2014-11-24CVE-2014-9015: Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.46%
82.8th percentile
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| drupal | drupal | >= 6.0 < 6.34 | 6.34 |
| drupal | drupal | >= 7.0 < 7.34 | 7.34 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26gr-c7rc-wwqj: Drupal 6
ghsa_unreviewed·2022-05-14
CVE-2014-9015 [MEDIUM] GHSA-26gr-c7rc-wwqj: Drupal 6
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
OSV
CVE-2014-9015: Drupal 6
osv·2014-11-24·CVSS 6.8
CVE-2014-9015 [MEDIUM] CVE-2014-9015: Drupal 6
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9015 drupal7: drupal: session hijacking vulnerability (SA-CORE-2014-006) [fedora-all]
bugzilla·2014-11-20·CVSS 6.8
CVE-2014-9015 [MEDIUM] CVE-2014-9015 drupal7: drupal: session hijacking vulnerability (SA-CORE-2014-006) [fedora-all]
CVE-2014-9015 drupal7: drupal: session hijacking vulnerability (SA-CORE-2014-006) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2014-9015 drupal6: drupal: session hijacking vulnerability (SA-CORE-2014-006) [epel-all]
bugzilla·2014-11-20·CVSS 6.8
CVE-2014-9015 [MEDIUM] CVE-2014-9015 drupal6: drupal: session hijacking vulnerability (SA-CORE-2014-006) [epel-all]
CVE-2014-9015 drupal6: drupal: session hijacking vulnerability (SA-CORE-2014-006) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2014-9015 drupal: session hijacking vulnerability (SA-CORE-2014-006)
bugzilla·2014-11-20·CVSS 6.8
CVE-2014-9015 [MEDIUM] CVE-2014-9015 drupal: session hijacking vulnerability (SA-CORE-2014-006)
CVE-2014-9015 drupal: session hijacking vulnerability (SA-CORE-2014-006)
It was reported [1] that Drupal core 6.x versions prior to 6.34, and Drupal core 7.x versions prior to 7.34 have session hijacking vulnerability.
A specially crafted request can give a user access to another user's session, allowing an attacker to hijack a random session.
This attack is known to be possible on certain Drupal 7 sites which serve both HTTP and HTTPS content ("mixed-mode"), but it is possible there are other attack vectors for both Drupal 6 and Drupal 7.
[1]: https://www.drupal.org/SA-CORE-2014-006
Discussion:
Created drupal7 tracking bugs for this issue:
Affects: fedora-all [bug 1166249]
Affects: epel-all [bug 1166250]
---
Created drupal6 tracking bugs for this issue:
Affects: fedora-all [bug 1
Bugzilla
CVE-2014-9015 drupal6: drupal: session hijacking vulnerability (SA-CORE-2014-006) [fedora-all]
bugzilla·2014-11-20·CVSS 6.8
CVE-2014-9015 [MEDIUM] CVE-2014-9015 drupal6: drupal: session hijacking vulnerability (SA-CORE-2014-006) [fedora-all]
CVE-2014-9015 drupal6: drupal: session hijacking vulnerability (SA-CORE-2014-006) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2014-9015 drupal7: drupal: session hijacking vulnerability (SA-CORE-2014-006) [epel-all]
bugzilla·2014-11-20·CVSS 6.8
CVE-2014-9015 [MEDIUM] CVE-2014-9015 drupal7: drupal: session hijacking vulnerability (SA-CORE-2014-006) [epel-all]
CVE-2014-9015 drupal7: drupal: session hijacking vulnerability (SA-CORE-2014-006) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
http://secunia.com/advisories/59164http://secunia.com/advisories/59814http://www.debian.org/security/2014/dsa-3075http://www.openwall.com/lists/oss-security/2014/11/20/21http://www.openwall.com/lists/oss-security/2014/11/20/3https://www.drupal.org/SA-CORE-2014-006http://secunia.com/advisories/59164http://secunia.com/advisories/59814http://www.debian.org/security/2014/dsa-3075http://www.openwall.com/lists/oss-security/2014/11/20/21http://www.openwall.com/lists/oss-security/2014/11/20/3https://www.drupal.org/SA-CORE-2014-006
2014-11-24
Published