CVE-2019-1487

MEDIUM

Microsoft Authentication Library for Android 0.3.1-Alpha and later - Information Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0400
EPSS Percentile 89.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
microsoft/authentication_library 0.3.1 alpha
microsoft/authentication_library < 0.2.2
Published Dec 10, 2019
Tracked Since Feb 18, 2026