Information Disclosure Vulnerability in Microsoft Authentication Library for Android
CVE-2019-1487
6.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 December 2019
Summary
An information disclosure vulnerability exists in Android applications utilizing the Microsoft Authentication Library (MSAL) version 0.3.1-Alpha and newer. This vulnerability can be exploited under specified conditions, potentially exposing sensitive information used in authentication processes. Developers using MSAL should ensure they are following best security practices to mitigate any risk.
Affected Version(s)
Microsoft Authentication Library (MSAL) for Android = unspecified
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved