CVE-2024-43477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
23/08/2024
Last modified:
29/01/2025

Description

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools