New Blog Post | Guidance for Azure Active Directory keyCredential property Information Disclosure

Microsoft

SEC20_Security_004-900x360.jpg

Guidance for Azure Active Directory (AD) keyCredential property Information Disclosure in Applicatio...

Microsoft recently mitigated an information disclosure issue, CVE-2021-42306, to prevent private key data from being stored by some Azure services in the keyCredentials property of an Azure Active Directory (Azure AD) Application and/or Service Principal, and prevent reading of private key data previously stored in the keyCredentials property.
The keyCredentials property is used to configure an application’s authentication credentials. It is accessible to any user or service in the organization’s Azure AD tenant with read access to application metadata.

0 Replies