CVE-2015-5505

Severity

68%

Complexity

86%

Confidentiality

106%

The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.

The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.

CVSS 2.0 Base Score 6.8. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).

Overview

Type

Codfront Labs HTTP Strict Transport Security

First reported 9 years ago

2015-08-18 18:00:00

Last updated 7 years ago

2017-07-26 01:29:00

Affected Software

Codfront Labs HTTP Strict Transport Security 6.x-1.0 for Drupal

6.x-1.0
drupal

Codfront Labs HTTP Strict Transport Security 6.x-1.0 Release Candidate 1 for Drupal

6.x-1.0
drupal

Codfront Labs HTTP Strict Transport Security 7.x-1.0 for Drupal

7.x-1.0
drupal

Codfront Labs HTTP Strict Transport Security 7.x-1.0 Release Candidate 1 for Drupal

7.x-1.0
drupal

Codfront Labs HTTP Strict Transport Security 7.x-1.1 for Drupal

7.x-1.1
drupal

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.