PT-2024-21638 · Microsoft · Msal.Net
Ntc-Swiss-Team
·
Published
2024-04-16
·
Updated
2024-04-17
·
CVE-2024-27086
CVSS v3.1
3.9
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MSAL.NET versions 4.48.0 through 4.60.0
Description
A malicious application running on a customer Android device can cause local denial of service against applications that were built using MSAL.NET for authentication on the same device, due to incorrect activity export configuration. This can prevent the user of the legitimate application from logging in. Additionally, a malicious application can inject HTML/JavaScript in an embedded web view exported by affected applications.
Recommendations
For MSAL.NET versions 4.48.0 through 4.60.0, update to MSAL.NET version 4.60.1 or later to resolve the issue.
As a temporary workaround, developers may explicitly mark the MSAL.NET activity non-exported by setting
android:exported="false" in the activity configuration.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Msal.Net