{"id":"GHSA-5g66-628f-7cvj","summary":"Omniauth::MicrosoftGraph Account takeover (nOAuth)","details":"### Summary\nThe implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to [nOAuth](https://www.descope.com/blog/post/noauth) misconfiguration in cases when the `email` is used as a trusted user identifier\n","aliases":["CVE-2024-21632"],"modified":"2026-09-10T03:50:04.829983040Z","published":"2024-01-03T21:46:46Z","database_specific":{"nvd_published_at":"2024-01-02T22:15:10Z","cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-03T21:46:46Z"},"references":[{"type":"WEB","url":"https://github.com/synth/omniauth-microsoft_graph/security/advisories/GHSA-5g66-628f-7cvj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21632"},{"type":"WEB","url":"https://github.com/synth/omniauth-microsoft_graph/commit/5ffd62690ca0e46978f2fc7d83b18d28edde7795"},{"type":"WEB","url":"https://github.com/synth/omniauth-microsoft_graph/commit/f132078389612b797c872b45bd0e0b47382414c1"},{"type":"PACKAGE","url":"https://github.com/synth/omniauth-microsoft_graph"},{"type":"WEB","url":"https://www.descope.com/blog/post/noauth"}],"affected":[{"package":{"name":"omniauth-microsoft_graph","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-microsoft_graph"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0"}]}],"versions":["0.1.0","0.1.1","0.2.0","0.2.1","0.3.0","0.3.1","0.3.2","0.3.3","1.0.0","1.1.0","1.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-5g66-628f-7cvj/GHSA-5g66-628f-7cvj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}]}