Azure Active Directory Authentication Library Elevation of Privilege Vulnerability
Published Aug 14, 2019
8.8
HIGHCVSS 3.0
EPSS 3.80%
Description
An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The authenticated attacker can exploit this vulneraiblity by accessing a service configured for On-Behalf-Of flow that assigns incorrect tokens. This security update addresses the vulnerability by removing fallback cache look-up for On-Behalf-Of scenarios.
Affected products
-
- Version 5.0.0StatusaffectedConstraints<publication
- Version
-
- Version 5.0.0StatusaffectedConstraints<publication
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Adal.net | n/a |
| ||||||
| Microsoft | Nuget 5.2.0 | n/a |
|
- ≥ 5.0.5 · < 5.2.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (3)
- https://github.com/advisories/GHSA-xc6x-cq47-9chw Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-1258
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1258 x_refsource_MISCPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-xc6x-cq47-9chw | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-1258 | ||
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1258 | x_refsource_MISCPatchVendor Advisory |
Change history (0)
No recorded changes yet.