all InfoSec news
Power Platform Custom Code information disclosure
Aug. 4, 2023, midnight |
The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org
Code functions used for custom connectors, thereby allowing cross-tenant information
disclosure of secrets or other sensitive information if these were embedded in a
Custom Code function. The issue occurred as a result of insufficient access control
to Azure Function hosts, which are launched as part of the creation and operation of
custom connectors in Microsoft’s Power Platform. An attacker who determined the
hostname of the Azure Function associated …
access access control azure code connectors control disclosure embedded function functions information information disclosure issue platform power result secrets sensitive information unauthorized access vulnerability
More from www.cloudvulndb.org / The Open Cloud Vulnerability & Security Issue Database
AWS Amplify IAM role publicly assumable exposure
1 week, 6 days ago |
www.cloudvulndb.org
Azure Site Recovery privilege escalation
2 months, 2 weeks ago |
www.cloudvulndb.org
Azure HDInsight privilege escalation and DoS vulnerabilities
2 months, 3 weeks ago |
www.cloudvulndb.org
Azure Pipelines Agent poisoned pipeline execution
4 months, 1 week ago |
www.cloudvulndb.org
Amazon WorkSpaces Windows client credential logging
6 months, 3 weeks ago |
www.cloudvulndb.org
Power Platform Custom Code information disclosure
8 months, 3 weeks ago |
www.cloudvulndb.org
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Associate Compliance Advisor
@ SAP | Budapest, HU, 1031
DevSecOps Engineer
@ Qube Research & Technologies | London
Software Engineer, Security
@ Render | San Francisco, CA or Remote (USA & Canada)
Associate Consultant
@ Control Risks | Frankfurt, Hessen, Germany
Senior Security Engineer
@ Activision Blizzard | Work from Home - CA