Information Disclosure Vulnerability in Microsoft Authentication Library for Android
CVE-2019-1487

6.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 December 2019

Summary

An information disclosure vulnerability exists in Android applications utilizing the Microsoft Authentication Library (MSAL) version 0.3.1-Alpha and newer. This vulnerability can be exploited under specified conditions, potentially exposing sensitive information used in authentication processes. Developers using MSAL should ensure they are following best security practices to mitigate any risk.

Affected Version(s)

Microsoft Authentication Library (MSAL) for Android = unspecified

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.