Vulnerability Description
The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Services Project | Services | <= 7.x-3.9 |
Related Weaknesses (CWE)
References
- http://cgit.drupalcode.org/services/commit/?id=809aafaVendor Advisory
- https://www.drupal.org/node/2344389Vendor Advisory
- https://www.drupal.org/node/2344423Vendor Advisory
- http://cgit.drupalcode.org/services/commit/?id=809aafaVendor Advisory
- https://www.drupal.org/node/2344389Vendor Advisory
- https://www.drupal.org/node/2344423Vendor Advisory
FAQ
What is CVE-2014-9152?
CVE-2014-9152 is a vulnerability with a CVSS score of 7.5 (HIGH). The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess t...
How severe is CVE-2014-9152?
CVE-2014-9152 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9152?
Check the references section above for vendor advisories and patch information. Affected products include: Services Project Services.