CVE-2024-35255

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
11/06/2024
Last modified:
20/06/2024

Description

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:authentication_library:*:*:*:*:*:java:*:* 1.15.1 (excluding)
cpe:2.3:a:microsoft:authentication_library:*:*:*:*:*:node.js:*:* 2.9.2 (including)
cpe:2.3:a:microsoft:authentication_library:*:*:*:*:*:.net:*:* 4.61.3 (excluding)
cpe:2.3:a:microsoft:azure_identity_sdk:*:*:*:*:*:go:*:* 1.6.0 (excluding)
cpe:2.3:a:microsoft:azure_identity_sdk:*:*:*:*:*:c\+\+:*:* 1.8.0 (excluding)
cpe:2.3:a:microsoft:azure_identity_sdk:*:*:*:*:*:.net:*:* 1.11.4 (excluding)
cpe:2.3:a:microsoft:azure_identity_sdk:*:*:*:*:*:java:*:* 1.12.2 (excluding)
cpe:2.3:a:microsoft:azure_identity_sdk:*:*:*:*:*:python:*:* 1.16.1 (excluding)
cpe:2.3:a:microsoft:azure_identity_sdk:*:*:*:*:*:javascript:*:* 4.2.1 (excluding)


References to Advisories, Solutions, and Tools