logo

CVE-2016-7191 passport-azure-ad

Package

Manager: npm
Name: passport-azure-ad
Vulnerable Version: >=1.0.0 <1.4.6 || =2.0.0 || >=2.0.0 <2.0.1

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.10511 pctl0.92969

Details

Authentication Bypass in passport-azure-ad Affected versions of `passport-azure-ad` do not recognize the `validateIssuer` setting, which allows remote attackers to bypass authentication via a crafted token. ## Recommendation Version 1.x: Update to version 1.4.6 or later. Version 2.x: Update to version 2.0.1 or later.

Metadata

Created: 2018-07-26T15:53:31Z
Modified: 2021-09-02T19:18:46Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-73jp-3c67-hjfv/GHSA-73jp-3c67-hjfv.json
CWE IDs: ["CWE-287"]
Alternative ID: GHSA-73jp-3c67-hjfv
Finding: F006
Auto approve: 1