CVE-2016-7191
HIGHMicrosoft Azure Active Directory Passport - Authentication Bypass
Title source: ruleDescription
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.
Scores
CVSS v3
8.1
EPSS
0.0380
EPSS Percentile
87.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-287
Status
draft
Affected Products (19)
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
microsoft/azure_active_directory_passport
... and 4 more
Timeline
Published
Sep 28, 2016
Tracked Since
Feb 18, 2026