CVE-2019-1487High

Microsoft Authentication Library for Android Information Disclosure Vulnerability

Published
December 10, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions. This vulnerability could result in sensitive data being exposed. To exploit this vulnerability an attacker would need to be authenticated to have rights to view the sensitive data. This security update addresses the vulnerability by modifying how the data is sanitized.

🎯 Affected products1

  • Microsoft Authentication Library (MSAL) for Android

✅ Remediation

KBGithub Repository (Security Update)

🔗 References (2)