« Volver al listado

CVE-2009-4527

Estado: ModificadaMedia (4.6)—

The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4527",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-12-31T19:30:00.577",
  "references": [
    {
      "url": "http://drupal.org/node/604488",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37057",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/36684",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/2919",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53779",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/604488",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37057",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36684",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/2919",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53779",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser."
    },
    {
      "lang": "es",
      "value": "El módulo de autenticación Shibboleth v5.x anterior a v5.x-3.4 y v6.x anterior a v6.x-3.2, un módulo para Drupal, no elimina adecuadamente los privilegios otorgados estáticamente después un cierre de sesión u otro cambio de sesión, lo que permite a atacantes próximos físicamente obtener privilegios utilizando un navegador web desatendido.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:13:49.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15E77DE1-B275-47F1-95FB-C7585471BBB3"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88ADE30B-7B9D-4141-A5AA-2A0E3331B3AE"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFC7441B-D570-458B-BB6E-82358F333E5D"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1795BC5F-A8F9-4546-B319-5352753198CF"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D8815F9-BC9E-445E-80FF-5B4C3B62224F"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-2.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D936BB56-06D1-4730-916B-81B791B489C9"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B197C383-71B5-4891-A67C-A1D357007304"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:5.x-3.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "256F4AC0-C2A5-43FD-B164-2174EC92EDA6"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7155A403-16B9-4A2C-B035-059E42F3A3D1"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A364AA96-0ACC-488A-8DF4-814807F5FCFC"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71CCBBD7-04BC-4B2B-BE53-F9AAAB9A8F4E"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "083B1A21-9FC9-4593-82AC-59FA9BFE7743"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-2.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4A2F6C6-7323-4F7E-B599-03D78158A9CE"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC185FC1-4AC8-47A4-BEFD-97092FAA93EF"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-3.0:1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A410B66E-99B3-472D-B5D1-CA0506D7A060"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "925B50D8-D35C-415A-B66E-23CD80891650"
            },
            {
              "criteria": "cpe:2.3:a:niif:shib_auth:6.x-3.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ADBB3C3-FEA1-43D2-9F4E-DB663A2EEEDC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}