May 7, 2024, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Multiple vulnerabilities were uncovered in Azure Health Bot service, Microsoft's health chatbot platform.
These could have potentially exposed sensitive user data and granted attackers extensive control, allowing
unrestricted code execution as root on the bot backend, unrestricted access to authentication secrets &
integration auth providers, unrestricted memory read in the bot backend, exposing sensitive secrets,
allowing cross-tenant data access and unrestricted deletion of other tenants' public resources.
These issues stemmed from various bugs related to URL sanitization, shared compute, and …

access amp attackers auth authentication azure backend bot chatbot code code execution control data exposed exposing health injection integration memory microsoft platform root secrets sensitive service uncovered user data vulnerabilities

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC