June 20, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Descope identified a possible misconfiguration in Azure AD which could lead to misuse of the "Log in with Microsoft"
authentication method on a web app. If an application relies on email attribute claims for authentication (which is
against best practice) and also merges user accounts without proper validation, an attacker could falsify an email
claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant
applications with users that used an email address with …

accounts app application authentication azure azure ad best practice claim claims control email log microsoft misconfiguration noauth practice validation web web app

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States