CVE-2024-27086
Last modified
CVE-2024-27086 is a low-severity vulnerability rated 3.9/10 on the CVSS scale. The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity vulnerability. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity vulnerability. A malicious application running on a customer Android device can cause local denial of service against applications that were built using MSAL.NET for authentication on the same device (i.e., prevent the user of the legitimate application from logging in) due to incorrect activity export configuration. MSAL.NET version 4.60.1 includes the fix. As a workaround, a developer may explicitly mark the MSAL.NET activity non-exported.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-27086?
How severe is CVE-2024-27086?
How do I fix CVE-2024-27086?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-27080In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2024-27081ESPHome is a system to control your ESP8266/ESP32. A securit…8.8
- CVE-2024-27082Cacti provides an operational monitoring and fault managemen…5.4
- CVE-2024-27083Flask-AppBuilder is an application development framework, bu…6.1
- CVE-2024-27084Rejected reason: This CVE is a duplicate of CVE-2024-1631.
- CVE-2024-27085Discourse is an open source platform for community discussio…6.5
- CVE-2024-27087Kirby is a content management system. The new link field int…5.4
- CVE-2024-27088es5-ext contains ECMAScript 5 extensions. Passing functions …5.5
- CVE-2024-27089Rejected reason: This candidate was withdrawn by its CNA. Fu…
- CVE-2024-2709A vulnerability was found in Tenda AC10U 15.03.06.49. It has…8.8
- CVE-2024-27090Decidim is a participatory democracy framework, written in R…5.3
- CVE-2024-27091GeoNode is a geospatial content management system, a platfor…6.1
Are you affected by CVE-2024-27086?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
