{"id":"CVE-2019-1258","details":"An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user.\nThe authenticated attacker can exploit this vulneraiblity by accessing a service configured for On-Behalf-Of flow that assigns incorrect tokens.\nThis security update addresses the vulnerability by removing fallback cache look-up for On-Behalf-Of scenarios.","aliases":["GHSA-xc6x-cq47-9chw"],"modified":"2026-07-08T05:55:49.803705549Z","published":"2019-08-14T21:15:19.173Z","database_specific":{"unresolved_ranges":[{"vendor_product":"microsoft:nuget","cpes":["cpe:2.3:a:microsoft:nuget:5.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.2.0"},{"last_affected":"5.2.0"}],"source":"CPE_STRING"}]},"references":[{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1258"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/azuread/azure-activedirectory-library-for-dotnet","events":[{"introduced":"99f1dd308ad4ad8aeb3ca90014e0f1c12e219490"},{"fixed":"e548649d705daadfc1306f5c6db3b0e81d50b001"},{"introduced":"df6c2ddacc27ecf726e64d6d4bedb05053250b90"},{"last_affected":"d80b70dff7cdbc001b3e604019371daac80d9211"}],"database_specific":{"cpe":["cpe:2.3:a:microsoft:active_directory_authentication_library:*:*:*:*:*:.net:*:*","cpe:2.3:a:microsoft:active_directory_authentication_library:5.0.0:preview:*:*:*:.net:*:*","cpe:2.3:a:microsoft:active_directory_authentication_library:5.0.1:preview:*:*:*:.net:*:*","cpe:2.3:a:microsoft:active_directory_authentication_library:5.0.2:preview:*:*:*:.net:*:*","cpe:2.3:a:microsoft:active_directory_authentication_library:5.0.3:preview:*:*:*:.net:*:*"],"extracted_events":[{"introduced":"5.0.5"},{"fixed":"5.2.0"},{"introduced":"5.0.0-preview"},{"last_affected":"5.0.0-preview"},{"introduced":"5.0.1-preview"},{"last_affected":"5.0.1-preview"},{"introduced":"5.0.2-preview"},{"last_affected":"5.0.2-preview"},{"introduced":"5.0.3-preview"},{"last_affected":"5.0.3-preview"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["5.0.0-preview","5.0.1-preview","5.0.2-preview","5.0.3-preview","5.1.1","5.1.0","5.0.5","ADAL-v5.0.1-preview","ADAL-v5.0.0-preview"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1258.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}