PT-2016-7261 · Microsoft · Passport-Azure-Ad
Published
2016-09-28
·
Updated
2018-07-26
·
CVE-2016-7191
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
passport-azure-ad versions 1.x through 1.4.5
passport-azure-ad versions 2.x through 2.0.0
Description
The issue allows remote attackers to bypass authentication via a crafted token because the
validateIssuer setting is not recognized.Recommendations
Update to version 1.4.6 or later for version 1.x.
Update to version 2.0.1 or later for version 2.x.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Passport-Azure-Ad