Skip to content

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Moderate severity GitHub Reviewed Published Jun 11, 2024 to the GitHub Advisory Database • Updated Aug 7, 2024

Package

npm @azure/identity (npm)

Affected versions

< 4.2.1

Patched versions

4.2.1
npm @azure/msal-node (npm)
>= 2.7.0, < 2.9.2
2.9.2
nuget Azure.Identity (NuGet)
< 1.11.4
1.11.4
nuget Microsoft.Identity.Client (NuGet)
>= 4.49.1, < 4.60.4
>= 4.61.0, < 4.61.3
4.60.4
4.61.3
pip azure-identity (pip)
< 1.16.1
1.16.1
maven com.azure:azure-identity (Maven)
< 1.12.2
1.12.2
maven com.microsoft.azure:msal4j (Maven)
>= 1.14.4-beta, < 1.15.1
1.15.1
gomod github.com/Azure/azure-sdk-for-go/sdk/azidentity (Go)
< 1.6.0
1.6.0
Published by the National Vulnerability Database Jun 11, 2024
Published to the GitHub Advisory Database Jun 11, 2024
Reviewed Jun 11, 2024
Last updated Aug 7, 2024

Severity

Moderate
5.5
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CVE ID

CVE-2024-35255

GHSA ID

GHSA-m5vv-6r4h-3vj9

Source code

No known source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.