Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microsoft Subscribe
Filtered by product Azure Active Directory Passport
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-7191 1 Microsoft 1 Azure Active Directory Passport 2017-07-29 4.3 MEDIUM 8.1 HIGH
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.