Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and received credentials are stored as world readable. This is fixed in versions 0.9.22 and 1.2.0. To work around this issue, remove all read access to Himmelblau caches for all users except for owners.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Aug 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Himmelblau-idm
Himmelblau-idm himmelblau |
|
Vendors & Products |
Himmelblau-idm
Himmelblau-idm himmelblau |
Thu, 07 Aug 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and received credentials are stored as world readable. This is fixed in versions 0.9.22 and 1.2.0. To work around this issue, remove all read access to Himmelblau caches for all users except for owners. | |
Title | Himmelblau's Kerberos credential cache collection is world readable | |
Weaknesses | CWE-522 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-07T00:02:09.263Z
Updated: 2025-08-07T14:32:00.582Z
Reserved: 2025-07-31T17:23:33.476Z
Link: CVE-2025-54882

Updated: 2025-08-07T14:31:53.398Z

Status : Awaiting Analysis
Published: 2025-08-07T01:15:26.527
Modified: 2025-08-07T21:26:37.453
Link: CVE-2025-54882

No data.