Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8g9c-28fc-mcx2

Опубликовано: 09 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Duplicate Advisory: Microsoft Identity Denial of service vulnerability

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-59j7-ghrg-fj52. This link is maintained to preserve external references.

Original Description

Impact

An attacker could exploit this vulnerability by crafting a malicious JSON Web Encryption (JWE) token with a high compression ratio. This token, when processed by a server, leads to excessive memory allocation and processing time during decompression, causing a denial-of-service (DoS) condition.

It's important to note that the attacker must have access to the public encrypt key registered with the IDP(Entra ID) for successful exploitation.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? A scope change (S:C) in the CVSS metric indicates that successful exploitation of this vulnerability could extend beyond the immediate processing of malicious tokens, affecting the overall availability of the system by causing a denial-of-service (DoS) condition.

Patches

The vulnerability has been fixed. Users should update all their Microsoft.IdentityModel versions to 7.1.2 (for 7x) or higher, 6.34.0 (for 6x) or higher, and 5.7.0 (for 5x).

Workarounds

No, users must upgrade.

References

https://aka.ms/IdentityModel/Jan2024/zip

Пакеты

Наименование

Microsoft.IdentityModel.JsonWebTokens

nuget
Затронутые версииВерсия исправления

< 5.7.0

5.7.0

Наименование

Microsoft.IdentityModel.JsonWebTokens

nuget
Затронутые версииВерсия исправления

>= 6.5.0, < 6.34.0

6.34.0

Наименование

Microsoft.IdentityModel.JsonWebTokens

nuget
Затронутые версииВерсия исправления

>= 7.0.0-preview, < 7.1.2

7.1.2

Наименование

System.IdentityModel.Tokens.Jwt

nuget
Затронутые версииВерсия исправления

< 5.7.0

5.7.0

Наименование

System.IdentityModel.Tokens.Jwt

nuget
Затронутые версииВерсия исправления

>= 6.5.0, < 6.34.0

6.34.0

Наименование

System.IdentityModel.Tokens.Jwt

nuget
Затронутые версииВерсия исправления

>= 7.0.0-preview, < 7.1.2

7.1.2

6.8 Medium

CVSS3

Дефекты

CWE-20

6.8 Medium

CVSS3

Дефекты

CWE-20