CVE-2024-38190: Power Platform Information Disclosure Vulnerability
Published Oct 15, 2024
·Updated
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
Other sources
Power Platform Information Disclosure Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Power Platform
Microsoft Power Platform
Remediation
Event History
Oct 15, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·10:46 PM
Data Sourced
via MITRE·10:46 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38190?
CVE-2024-38190 is considered to have a high severity due to the potential exposure of sensitive information.
2
Who is affected by CVE-2024-38190?
CVE-2024-38190 affects users of Microsoft Power Platform who may be exposed to unauthorized data access.
3
How do I fix CVE-2024-38190?
To fix CVE-2024-38190, ensure that all security updates from Microsoft for Power Platform are applied.
4
What kind of attacks can CVE-2024-38190 enable?
CVE-2024-38190 allows unauthenticated attackers to conduct network attacks that expose sensitive information.
5
Is authentication required to exploit CVE-2024-38190?
No, CVE-2024-38190 can be exploited by attackers without authentication.