Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and received credentials are stored as world readable. This is fixed in versions 0.9.22 and 1.2.0. To work around this issue, remove all read access to Himmelblau caches for all users except for owners.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:himmelblau-idm:himmelblau:*:*:*:*:*:*:*:* |
Thu, 07 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Aug 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Himmelblau-idm
Himmelblau-idm himmelblau |
|
| Vendors & Products |
Himmelblau-idm
Himmelblau-idm himmelblau |
Thu, 07 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and received credentials are stored as world readable. This is fixed in versions 0.9.22 and 1.2.0. To work around this issue, remove all read access to Himmelblau caches for all users except for owners. | |
| Title | Himmelblau's Kerberos credential cache collection is world readable | |
| Weaknesses | CWE-522 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-07T00:02:09.263Z
Updated: 2025-08-07T14:32:00.582Z
Reserved: 2025-07-31T17:23:33.476Z
Link: CVE-2025-54882
Updated: 2025-08-07T14:31:53.398Z
Status : Analyzed
Published: 2025-08-07T01:15:26.527
Modified: 2025-10-09T17:36:51.513
Link: CVE-2025-54882
No data.