CVE-2007-1651
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/03/2007
Last modified:
09/04/2025
Description
Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enabled site via unspecified vectors related to an arbitrary remote web site and cached tokens, after the user has signed into an OpenID server, logged into the OpenID enabled site, and then logged out of the OpenID enabled site.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openid:openid:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://janrain.com/blog/2007/03/22/myopenid-security-fix/
- http://openid.net/pipermail/security/2007-March/000286.html
- http://openid.net/pipermail/security/2007-March/000288.html
- http://openid.net/pipermail/security/2007-March/000291.html
- http://openid.net/pipermail/security/2007-March/000306.html
- http://openid.net/pipermail/security/2007-March/000311.html
- http://osvdb.org/43600
- http://janrain.com/blog/2007/03/22/myopenid-security-fix/
- http://openid.net/pipermail/security/2007-March/000286.html
- http://openid.net/pipermail/security/2007-March/000288.html
- http://openid.net/pipermail/security/2007-March/000291.html
- http://openid.net/pipermail/security/2007-March/000306.html
- http://openid.net/pipermail/security/2007-March/000311.html
- http://osvdb.org/43600



