CVE-2019-1487Sensitive Information Exposure in Microsoft Authentication Library

Severity
6.5MEDIUMNVD
EPSS
3.2%
top 12.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 24

Description

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v223-v69f-prp5: An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 02022-05-24
CVEList
CVE-2019-1487: An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 02019-12-10

📋Vendor Advisories

1
Microsoft
Microsoft Authentication Library for Android Information Disclosure Vulnerability2019-12-10
CVE-2019-1487 — Sensitive Information Exposure | cvebase