Security News > 2021 > August > Microsoft Power Apps misconfiguration exposes data from 38 million records

Microsoft Power Apps misconfiguration exposes data from 38 million records
2021-08-24 13:52

A lack of proper security configuration with Microsoft's Power Apps has led to the exposure of data from some 38 million records, according to security firm UpGuard.

Among the organizations whose data was exposed were government agencies in Indiana, Maryland and New York City, as well as private companies such as American Airlines, J.B. Hunt and even Microsoft itself.

Microsoft Power Apps is a low-code development tool designed to help people with little programming experience build web and mobile apps for their organizations.

As part of the process, Microsoft allows customers to set up Power Apps portals as public websites to give internal and external users secure access to the required data.

To allow access to the data, Power Apps uses an OData API. The API retrieves data from Power Apps lists, which pull the data from tables in a database.

The report contained the steps required to identify OData feeds that allowed anonymous access to list data and URLs for accounts that were exposing sensitive data.


News URL

https://www.techrepublic.com/article/microsoft-power-apps-misconfiguration-exposes-data-from-38-million-records/#ftag=RSS56d97e7

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 381 51 1408 2910 175 4544