CVE-2021-42306
published 2021-11-24CVE-2021-42306: An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
3.08%
86.3th percentile
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application.
Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application.
Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information.
For more details on this issue, please refer to the MSRC Blog Entry.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_active_directory | < 2021-10-30 | 2021-10-30 |
| microsoft | azure_active_directory | — | — |
| microsoft | azure_active_site_recovery | < 2021-11-01 | 2021-11-01 |
| microsoft | azure_automation | < 2021-10-15 | 2021-10-15 |
| microsoft | azure_automation | >= 1.0.0 < publication | publication |
| microsoft | azure_migrate | < 2021-11-02 | 2021-11-02 |
| microsoft | azure_migrate | — | — |
| microsoft | azure_site_recovery | — | — |
| msrc | azure_active_directory | — | — |
| msrc | azure_automation | — | — |
| msrc | azure_migrate | — | — |
| msrc | azure_site_recovery | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxjx-p5m9-q5fr: Azure Active Directory Information Disclosure Vulnerability
ghsa_unreviewed·2021-11-25
CVE-2021-42306 [MEDIUM] CWE-522 GHSA-vxjx-p5m9-q5fr: Azure Active Directory Information Disclosure Vulnerability
Azure Active Directory Information Disclosure Vulnerability
Microsoft
Azure Active Directory Information Disclosure Vulnerability
vendor_msrc·2021-11-09·CVSS 8.1
CVE-2021-42306 [HIGH] Azure Active Directory Information Disclosure Vulnerability
Azure Active Directory Information Disclosure Vulnerability
Description: An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application.
Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application.
Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information.
For more details on this issue, pleas
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-24
Published