CVE-2015-5505

medium
Published 2015-08-18 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2507563

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2507543

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2507539

Application impact

VendorProductVersionsFixed
codfront_labshttp_strict_transport_security6.x-1.0
codfront_labshttp_strict_transport_security6.x-1.x
codfront_labshttp_strict_transport_security7.x-1.0
codfront_labshttp_strict_transport_security7.x-1.1

References

CWEs

CWE-17

Verify integrity in audit chain (admin only). AS-IS.