Executive Summary



This vulnerability is currently undergoing analysis and not all information is available. Please check back soon to view the completed vulnerability summary
Informations
Name CVE-2025-24034 First vendor Publication 2025-01-23
Vendor Cve Last vendor Modification 2025-01-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to versions 0.7.15 and 0.8.3, Himmelblau is vulnerable to leaking credentials in debug logs. When debug logging is enabled, user access tokens are inadvertently logged, potentially exposing sensitive authentication data. Similarly, Kerberos Ticket-Granting Tickets (TGTs) are logged when debug logging is enabled. Both issues pose a risk of exposing sensitive credentials, particularly in environments where debug logging is enabled. Himmelblau versions 0.7.15 and 0.8.3 contain a patch that fixes both issues. Some workarounds are available for users who are unable to upgrade. For the **logon compliance script issue**, disable the `logon_script` option in `/etc/himmelblau/himmelblau.conf`, and avoid using the `-d` flag when starting the `himmelblaud` daemon. For the Kerberos CCache issue, one may disable debug logging globally by setting the `debug` option in `/etc/himmelblau/himmelblau.conf` to `false` and avoiding the `-d` parameter when starting `himmelblaud`.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24034

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-532 Information Leak Through Log Files

Sources (Detail)

https://github.com/himmelblau-idm/himmelblau/commit/1216804f15ce5dc74bb5da48b...
https://github.com/himmelblau-idm/himmelblau/releases/tag/0.7.15
https://github.com/himmelblau-idm/himmelblau/releases/tag/0.8.3
https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-p989-2f...
https://manpages.opensuse.org/Tumbleweed/himmelblau/himmelblau.conf.5.en.html
https://manpages.opensuse.org/Tumbleweed/himmelblau/himmelblaud.8.en.html
Source Url

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2025-01-23 21:20:30
  • First insertion