CVE-2024-21643

IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for the `SignedHttpRequest`protocol. This raises the possibility to make any remote or local `HTTP GET` request. The vulnerability has been fixed in Microsoft.IdentityModel.Protocols.SignedHttpRequest. Users should update all their Microsoft.IdentityModel versions to 7.1.2 (for 7x) or higher, 6.34.0 (for 6x) or higher.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:identitymodel_extensions:*:*:*:*:*:.net:*:*
cpe:2.3:a:microsoft:identitymodel_extensions:*:*:*:*:*:.net:*:*

History

21 Nov 2024, 08:54

Type Values Removed Values Added
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/6.34.0 - Release Notes () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/6.34.0 - Release Notes
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/7.1.2 - Release Notes () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/7.1.2 - Release Notes
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-rv9j-c866-gp5h - Vendor Advisory () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-rv9j-c866-gp5h - Vendor Advisory
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/wiki/jkucve - Mitigation, Third Party Advisory () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/wiki/jkucve - Mitigation, Third Party Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.1

19 Jan 2024, 22:53

Type Values Removed Values Added
First Time Microsoft identitymodel Extensions
Microsoft
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:microsoft:identitymodel_extensions:*:*:*:*:*:.net:*:*
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/6.34.0 - () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/6.34.0 - Release Notes
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/7.1.2 - () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/7.1.2 - Release Notes
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-rv9j-c866-gp5h - () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-rv9j-c866-gp5h - Vendor Advisory
References () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/wiki/jkucve - () https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/wiki/jkucve - Mitigation, Third Party Advisory

10 Jan 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Las extensiones IdentityModel para .NET proporcionan ensamblados para desarrolladores web que deseen utilizar proveedores de identidad federados para establecer la identidad de la persona que llama. Cualquiera que aproveche el protocolo `SignedHttpRequest` o `SignedHttpRequestValidator` es vulnerable. Microsoft.IdentityModel confía en el reclamo `jku` de forma predeterminada para el protocolo `SignedHttpRequest`. Esto plantea la posibilidad de realizar cualquier solicitud `HTTP GET` remota o local. La vulnerabilidad se ha solucionado en Microsoft.IdentityModel.Protocols.SignedHttpRequest. Los usuarios deben actualizar todas sus versiones de Microsoft.IdentityModel a 7.1.2 (para 7x) o superior, 6.34.0 (para 6x) o superior.

10 Jan 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-10 05:15

Updated : 2024-11-21 08:54


NVD link : CVE-2024-21643

Mitre link : CVE-2024-21643

CVE.ORG link : CVE-2024-21643


JSON object : View

Products Affected

microsoft

  • identitymodel_extensions
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')