ueberauth_microsoft is vulnerable to Insufficient Verification of Data Authenticity
45
Medium Risk
Affected versions of this package assume that the email field returned by the Microsoft OAuth provider is a verified email address, which can be unsafe because that attribute can be modified in Azure without actual verification, potentially allowing authentication as an arbitrary user. The patch updates the strategy to rely on a more trustworthy identifier (userPrincipalName) rather than unverified email, preventing this class of authentication spoofing.
You are affected if you are using a version that falls within the vulnerable range.
ueberauth_microsoft is vulnerable to Insufficient Verification of Data Authenticity in versions 0.1.0 - 0.24.0.
Upgrade the ueberauth_microsoft library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant