CVE-2007-6752

Priority
Low
Description
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in Drupal
7.12 and earlier allows remote attackers to hijack the authentication of
arbitrary users for requests that end a session via the user/logout URI.
NOTE: the vendor disputes the significance of this issue, by considering
the "security benefit against platform complexity and performance impact"
and concluding that a change to the logout behavior is not planned because
"for most sites it is not worth the trade-off."
References
Package
Upstream:needs-triage
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):needed
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu 14.10 (Utopic Unicorn):needed
Package
Upstream:needs-triage
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 14.10 (Utopic Unicorn):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2014-10-23 21:14:33 UTC (commit 8644)