Severity
6.8MEDIUM
EPSS
0.6%
top 30.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateApr 26

Description

Microsoft Identity Denial of service vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 2.3 | Impact: 4.0

Affected Packages20 packages

NVDmicrosoft/identity_model5.0.05.7.0+2
NuGetMicrosoft.IdentityModel.JsonWebTokens6.5.06.34.0+2

Patches

🔴Vulnerability Details

6
GHSA
python-jose denial of service via compressed JWE content2024-04-26
OSV
dotnet6, dotnet7, dotnet8 vulnerabilities2024-01-11
OSV
Microsoft ASP.NET Core project templates vulnerable to denial of service2024-01-09
OSV
CVE-2024-21319: Microsoft Identity Denial of service vulnerability2024-01-09
CVEList
Microsoft Identity Denial of service vulnerability2024-01-09

📋Vendor Advisories

4
Red Hat
python-jose: allows attackers to cause a denial of service2024-04-26
Ubuntu
.NET vulnerabilities2024-01-11
Red Hat
dotnet: .NET Denial of Service Vulnerability2024-01-10
Microsoft
Microsoft Identity Denial of service vulnerability2024-01-09
CVE-2024-21319 (MEDIUM CVSS 6.8) | Microsoft Identity Denial of servic | cvebase.io