Feb. 15, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Azure Active Directory B2C service (AD B2C) mistakenly implemented RSA encryption using the public part of the key pair instead of the private one.
This cryptographic flaw could have allowed an unauthenticated attacker to craft an OAuth refresh token for any AD B2C user account if they knew their public key.
Moreover, every AD B2C user's public key was recoverable through an unrelated vulnerability (though RSA encryption should not rely on public key secrecy regardless).
An attacker could redeem this …

account account compromise active directory azure azure active directory azure ad b2c compromise directory encryption flaw key oauth oauth refresh token private public public key refresh token rsa rsa encryption service the key token vulnerability

DevSecOps Engineer

@ Material Bank | Remote

Instrumentation & Control Engineer - Cyber Security

@ ASSYSTEM | Bridgwater, United Kingdom

Security Consultant

@ Tenable | MD - Columbia - Headquarters

Management Consultant - Cybersecurity - Internship

@ Wavestone | Hong Kong, Hong Kong

TRANSCOM IGC - Cybersecurity Engineer

@ IT Partners, Inc | St. Louis, Missouri, United States

Manager, Security Operations Engineering (EMEA)

@ GitLab | Remote, EMEA