Loading...
Loading...
The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser.
December 31, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-4527
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.