CVE-2015-3234: Debian Linux

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Drupal Drupal: version 6.0 only; version 6.1 only; version 6.2 only; version 6.3 only; version 6.4 only; version 6.5 only; …

Published 2015-06-22. Last modified 2026-06-17.