com.azure.spring:spring-cloud-azure-autoconfigure@6.4.0

  • latest version

    7.4.0

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    1 months ago

  • licenses detected

    • [4.0.0-beta.2,)
  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the com.azure.spring:spring-cloud-azure-autoconfigure package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Improper Authentication

    Affected versions of this package are vulnerable to Improper Authentication through the AadOidcIdTokenDecoderFactory and AadB2cOidcIdTokenDecoderFactory OIDC ID token decoders in the Spring Cloud Azure OAuth2 login components. An attacker can elevate privileges and sign in as an unauthorized tenant user by supplying a forged or tenant-mismatched ID token that is signed correctly but has an unvalidated iss claim and, in AAD multi-tenant flows, an inconsistent tid claim. This allows unauthorized access to applications that rely on the issuer or tenant claims to restrict which identities may authenticate.

    How to fix Improper Authentication?

    Upgrade com.azure.spring:spring-cloud-azure-autoconfigure to version 7.4.0 or higher.

    [,7.4.0)