4 results (0.004 seconds)

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

15 Oct 2024 — Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38190 • CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

25 Sep 2024 — Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs. This exposure occurs due to an error in the logging code that causes the `client_secret` to not be properly masked when logs are persisted or viewed. Users should upgrade to version 3.0.0 to rece... • https://github.com/microsoft/terraform-provider-power-platform/releases/tag/v3.0.0 • CWE-117: Improper Output Neutralization for Logs CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

27 Jun 2024 — An authenticated attacker can exploit an Untrusted Search Path vulnerability in Microsoft Dataverse to execute code over a network. Vulnerabilidad de ejecución remota de código de Microsoft Dataverse An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35260 • CWE-426: Untrusted Search Path •

CVSS: 9.6EPSS: 0%CPEs: 2EXPL: 0

12 Dec 2023 — Microsoft Power Platform Connector Spoofing Vulnerability Vulnerabilidad de suplantación de identidad del conector Microsoft Power Platform • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36019 • CWE-73: External Control of File Name or Path •