Authentication Bypass in passport-azure-ad
High severity
GitHub Reviewed
Published
Jul 26, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
>= 1.0.0, < 1.4.6
= 2.0.0
Patched versions
1.4.6
2.0.1
Description
Published to the GitHub Advisory Database
Jul 26, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Affected versions of
passport-azure-ad
do not recognize thevalidateIssuer
setting, which allows remote attackers to bypass authentication via a crafted token.Recommendation
Version 1.x: Update to version 1.4.6 or later.
Version 2.x: Update to version 2.0.1 or later.
References