Security vulnerability in passport-azure-ad > async AND passport-azure-ad > cache-manager > async
See original GitHub issueCore Library
Passport Azure AD (passport-azure-ad)
Core Library Version
4.3.1
Wrapper Library
Not Applicable
Wrapper Library Version
none
Description
The following dependency chaining originating in passport-azure-ad introduces a security vulnerability which is getting flagged by Whitesource: CVE-2021-43138 https://nvd.nist.gov/vuln/detail/CVE-2021-43138
Upgrade to version async - v3.2.2
passport-azure-ad > async passport-azure-ad > cache-manager > async
Error Message
No response
Msal Logs
No response
MSAL Configuration
N/A
Relevant Code Snippets
N/A
Reproduction Steps
N/A
Expected Behavior
N/A
Identity Provider
Azure AD / MSA
Browsers Affected (Select all that apply)
None (Server)
Regression
No response
Source
Internal (Microsoft)
Issue Analytics
- State:
- Created a year ago
- Reactions:2
- Comments:7 (5 by maintainers)
Top Results From Across the Web
getting error after successful authentication · Issue #471 - GitHub
I am checking the version of cache-manager, comparing it with v1.0 flow both are ... Security vulnerability in passport-azure-ad > async AND ......
Read more >passport-azure-ad-fixed - npm package - Snyk
All security vulnerabilities belong to production dependencies of direct and indirect packages. License: ISC. Security Policy: No.
Read more >Security update for the Passport-Azure-AD for Node.js library
This update addresses the vulnerability by correcting how ID tokens are validated when Passport strategies take advantage of Azure Active Directory. Frequently ...
Read more >deloittesolutions/passport-azure-ad NPM
passport-azure-ad has a known security vulnerability affecting versions <1.4.6 and 2.0.0. ... null); } // asynchronous verification, for effect... process.
Read more >About the Azure Active Directory Passport Library for Node.js
The vulnerability exists in web applications that use outdated versions of the Passport-Azure-AD for Node.js library.
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
Yes, planning to include this in our releases next week.
@AndrewHarrison92 You are correct, my mistake. #4724 will resolve that.