Bypassing SSRF Protection Leaks Sensitive Information
Key Information
- Vendor
- Microsoft
- Status
- Microsoft Copilot Studio
- Vendor
- CVE Published:
- 6 August 2024
Badges
Summary
The vulnerability CVE-2024-38206 in Microsoft's Copilot Studio tool allows an attacker to bypass Server-Side Request Forgery (SSRF) protection and leak sensitive cloud-based information across multiple tenants within cloud environments. The flaw can be exploited to access Microsoft's internal infrastructure and other internal hosts unrestricted on the local subnet. While the exploit has been mitigated, the potential impact on cloud data and services for multiple customers underscores the seriousness of the vulnerability. This vulnerability highlights the potential for attackers to abuse the tool's HTTP-request feature to gain elevated access to cloud data and resources.
Affected Version(s)
Microsoft Copilot Studio =
News Articles
CVSS V3.1
Timeline
- 👾
Exploit exists.
Risk change from: 6.5 to: 8.5 - (HIGH)
Vulnerability started trending.
First article discovered by null
Risk change from: 6.5 to: 8.5 - (HIGH)
Vulnerability published.