6.8
CVSSv2

CVE-2015-5505

Published: 18/08/2015 Updated: 26/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The HTTP Strict Transport Security (HSTS) module 6.x-1.x prior to 6.x-1.1 and 7.x-1.x prior to 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle malicious users to have unspecified impact via unknown vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codfront labs http strict transport security 7.x-1.0

codfront labs http strict transport security 7.x-1.1

codfront labs http strict transport security 6.x-1.0

codfront labs http strict transport security 6.x-1.x