« Volver al listado

CVE-2015-5505

Estado: ModificadaMedia (6.8)—

The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-5505",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-08-18T18:00:09.927",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/75276",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1037633",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2507539",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2507543",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2507563",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/07/04/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/75276",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1037633",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2507539",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2507543",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2507563",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-17"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the \"include subdomains\" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en el módulo HTTP Strict Transport Security (HSTS) 6.x-1.x en versiones anteriores a 6.x-1.1 y 7.x-1.x en versiones anteriores a 7.x-1.2 para Drupal, no implementa adecuadamente la directiva 'include subdomains', lo que causa que la política HSTS no se aplique a subdominios y permite a atacantes man-in-the-middle tener un impacto no especificado a través de vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-17T00:29:14.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:codfront_labs:http_strict_transport_security:6.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "763BE87D-0D10-45C2-B38D-0D9A6699A445"
            },
            {
              "criteria": "cpe:2.3:a:codfront_labs:http_strict_transport_security:6.x-1.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E72C6DB9-DBB9-41E5-B30D-0BBE5AC02B48"
            },
            {
              "criteria": "cpe:2.3:a:codfront_labs:http_strict_transport_security:6.x-1.x:dev:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF5976DF-6982-4D4C-AA88-4CE61199DEB4"
            },
            {
              "criteria": "cpe:2.3:a:codfront_labs:http_strict_transport_security:7.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D25C420-6A87-4824-BBB1-6AE9017476EC"
            },
            {
              "criteria": "cpe:2.3:a:codfront_labs:http_strict_transport_security:7.x-1.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "751AC80A-E9D3-44FE-8DFC-A06F2313FA94"
            },
            {
              "criteria": "cpe:2.3:a:codfront_labs:http_strict_transport_security:7.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "921CB3A5-4C85-4AAD-ACFB-D4CD271F12EE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}