Improper Authentication Affecting omniauth-microsoft_graph package, versions <2.0.0
Threat Intelligence
EPSS
0.07% (32nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-OMNIAUTHMICROSOFTGRAPH-6142750
- published 3 Jan 2024
- disclosed 2 Jan 2024
- credit Unknown
Introduced: 2 Jan 2024
CVE-2024-21632 Open this link in a new tabHow to fix?
Upgrade omniauth-microsoft_graph
to version 2.0.0 or higher.
Overview
omniauth-microsoft_graph is an omniauth provider for new Microsoft Graph API.
Affected versions of this package are vulnerable to Improper Authentication due to missing validation of the email
attribute. An attacker can take over accounts by exploiting the trust placed in the email
as a user identifier.
References
CVSS Scores
version 3.1