AzureAD/passport-azure-ad

AzureAD/passport-azure-ad

Releases44
Frequency1 month 2 weeks
Last Release
Stars422
The code for Passport Azure AD has been moved to the MSAL.js repo. Please open any issues or PRs at the link below.

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.