Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1487

Опубликовано: 10 дек. 2019
Источник: msrc
EPSS Низкий

Описание

Microsoft Authentication Library for Android Information Disclosure Vulnerability

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions. This vulnerability could result in sensitive data being exposed.

To exploit this vulnerability an attacker would need to be authenticated to have rights to view the sensitive data.

This security update addresses the vulnerability by modifying how the data is sanitized.

FAQ

What type of information could be disclosed by this vulnerability?

The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.

Обновления

ПродуктСтатьяОбновление
Microsoft Authentication Library (MSAL) for Android

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

EPSS

Процентиль: 87%
0.03396
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 6 лет назад

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'.

github
больше 3 лет назад

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость библиотеки аутентификации Microsoft Authentication Library (MSAL) for Android, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 87%
0.03396
Низкий