Vigil@nce - Drupal: two vulnerabilities of Google Authenticator login
May 2013 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can use two vulnerabilities of the Google
Authenticator login module of Drupal, in order to bypass the
authentication.
– Impacted products: Drupal
– Severity: 2/4
– Creation date: 16/05/2013
DESCRIPTION OF THE VULNERABILITY
Two vulnerabilities were announced in the Google Authenticator
login module of Drupal.
If a two-factor authentication is configured, an attacker can use
the login and password to authenticate, without needing the second
factor. [severity:2/4]
If a One Time Password authentication is configured, an attacker
can capture a session, and replay it. [severity:2/4]
An attacker can therefore use two vulnerabilities of the Google
Authenticator login module of Drupal, in order to bypass the
authentication.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
http://vigilance.fr/vulnerability/Drupal-two-vulnerabilities-of-Google-Authenticator-login-12835