VDB
BDU%3A2024-04789
BDU%3A2024-04789
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Уязвимость компонентов DefaultAzureCredential и ManagedIdentityCredential библиотек аутентификации Azure Identity Libraries и Microsoft Authentication Library, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
4.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp | Azure Identity Library for .NET, Azure Identity Library for C++, Azure Identity Library for Go, Azure Identity Library for Java, Azure Identity Library for JavaScript, Azure Identity Library for Python, Microsoft Authentication Library (MSAL) for .NET, Microsoft Authentication Library (MSAL) for Java, Microsoft Authentication Library (MSAL) for Node.js |
Timeline
- Jun 26, 2024 CVE Published
- Mar 19, 2026 Security Advisory
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35255 url
- https://www.nuget.org/packages/Microsoft.Identity.Client/ url
- https://mvnrepository.com/artifact/com.microsoft.azure/msal4j url
- https://www.npmjs.com/package/@azure/msal-node url
- https://learn.microsoft.com/en-us/dotnet/api/azure.identity.defaultazurecredential?view=azure-dotnet url
- https://learn.microsoft.com/ru-ru/dotnet/api/azure.identity.managedidentitycredential?view=azure-dotnet url