Authentication Bypass Affecting passport-azure-ad package, versions >=1.0.0 <1.4.6>=2.0.0 <2.0.1


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.51% (77th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDnpm:passport-azure-ad:20160824
  • published6 Dec 2016
  • disclosed23 Aug 2016
  • creditMicrosoft Azure AD Team

Introduced: 23 Aug 2016

CVE-2016-7191  (opens in a new tab)
CWE-592  (opens in a new tab)

How to fix?

Upgrade passport-azure-ad to version 1.4.6 or version 2.0.1 or higher, excluding version 2.0.0.

Overview

passport-azure-ad is a OIDC and Bearer Passport strategies for Azure Active Directory. The package mishandles ID token validation, allowing an attacker to create a specifically crafted token to the targeted host web application, containing valid user identities. With this flaw, the attacker bypasses the authentication to the hosts web application.

CVSS Scores

version 3.1