Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1258

Опубликовано: 14 авг. 2019
Источник: msrc
EPSS Средний

Описание

Azure Active Directory Authentication Library Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user.

The authenticated attacker can exploit this vulneraiblity by accessing a service configured for On-Behalf-Of flow that assigns incorrect tokens.

This security update addresses the vulnerability by removing fallback cache look-up for On-Behalf-Of scenarios.

Меры по смягчению последствий

The recommended mitigation for this vulnerability is to follow one cache per account while implementing ADAL On-Behalf-Of Flow.

See https://aka.ms/adal-net-cache-serialization-web-app-web-api for more information.

FAQ

ReferencesIdentification
Last version of the ADAL Library affected by this vulnerability5.1.1
First version of the ADAL Library affected by this vulnerability5.0.0 Preview
First version of the ADAL Library with this vulnerability addressed5.2.0

Обновления

ПродуктСтатьяОбновление
Nuget 5.2.0
ADAL.NET

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 93%
0.11137
Средний

Связанные уязвимости

CVSS3: 8.8
nvd
около 6 лет назад

An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The authenticated attacker can exploit this vulneraiblity by accessing a service configured for On-Behalf-Of flow that assigns incorrect tokens. This security update addresses the vulnerability by removing fallback cache look-up for On-Behalf-Of scenarios.

CVSS3: 8.8
github
около 6 лет назад

Vulnerability in Azure Active Directory Authentication Library

CVSS3: 8.8
fstec
около 6 лет назад

Уязвимость библиотеки ADAL.NET операционных систем Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 93%
0.11137
Средний