CVE-2016-7191
Published Sep 28, 2016
Last updated 7 years ago
Overview
- Description
- The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.
- Source
- secure@microsoft.com
- NVD status
- Modified
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14D9993C-1746-4E73-BA1A-BF22F2D7B79C" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B150E96A-EA8D-41E4-A383-14DA09E907A9" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7D40B5A-37AE-4B25-BB8E-A053085CF95A" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24C6F11F-93E7-4691-9245-9FAD916206FA" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D89F5AE-CF3D-4084-852D-F3A6B8768C96" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50FAA960-37B0-436B-AAFB-BE80D9795A98" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "086C4BE3-6751-4FE7-8D3A-F0810BB344DB" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13D902BB-4384-4409-8E87-F6695A3DB54C" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FAC1E176-C052-4A1A-B5ED-2463572A4DC6" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B71173BE-419B-408E-A42E-C5EE313089BC" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98BBF577-667C-4E8E-B300-F5015DC0B8ED" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36F2BC67-BD96-4925-B19C-4BB333391AC2" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1EFEC26-ABF9-4BB0-BE99-E846F5662857" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A36B10F0-AABA-4CAF-A47B-FBA58AE6ABB7" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA1DCDC5-81B1-45F1-A41F-88B780875456" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "869B6D37-E6C0-4621-9247-F51CD40BC0F2" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:1.4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25CE72AB-10F0-4A66-ACC2-0F5123E31DAE" }, { "criteria": "cpe:2.3:a:microsoft:azure_active_directory_passport:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E249FC87-D8D4-465E-A747-D5B5681BC36D" } ], "operator": "OR" } ] } ]