Skip to content

Account takeover (nOAuth)

High
synth published GHSA-5g66-628f-7cvj Jan 2, 2024

Package

bundler omniauth-microsoft_graph (RubyGems)

Affected versions

< 2.0.0

Patched versions

2.0.0

Description

Summary

The implementation did not validate the legitimacy of the email attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth misconfiguration in cases when the email is used as a trusted user identifier

Severity

High
8.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CVE ID

CVE-2024-21632

Weaknesses

No CWEs

Credits