Miggo Logo

CVE-2025-32016: Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs

4.7

CVSS Score
3.1

Basic Information

EPSS Score
0.00766%
Published
4/9/2025
Updated
4/10/2025
KEV Status
No
Technology
TechnologyC#

Technical Details

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
Microsoft.Identity.Webnuget>= 3.2.0, < 3.8.23.8.2
Microsoft.Identity.Abstractionsnuget>= 7.1.0, < 9.0.09.0.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t _W**t kin* o* vuln*r**ility is it? W*o is imp**t**?_ ****s*ription:** T*is vuln*r**ility *****ts *on*i**nti*l *li*nt *ppli**tions, in*lu*in* ***mons, w** *pps, *n* w** *PIs. Un**r sp**i*i* *ir*umst*n**s, s*nsitiv* in*orm*tion su** *s *li*

Reasoning

No *n*lysis *v*il**l*