infotechlead

Microsoft default settings in Power Apps expose user data: UpGuard

A default permission setting in Microsoft Power Apps might have exposed data of 38 million users’ online, cyber security researchers UpGuard reported.
Microsoft India Power Automate Desktop solutionUpGuard said the data included personal information used for Covid-19 contact tracing, vaccination appointments, social security numbers for job applicants, employee IDs, and millions of names and email addresses.

UpGuard notified 47 entities of exposures involving personal information, including governmental bodies like Indiana, Maryland, and New York City, and private companies like American Airlines, J.B. Hunt, and Microsoft, for a total of 38 million records across all portals.

The number of accounts exposing sensitive information indicates that the risk of this feature — the likelihood and impact of its misconfiguration — has not been adequately appreciated, UpGuard said in a blog post.

Microsoft Power Apps are a product for making low code, cloud-hosted business intelligence apps. Power Apps portals are a way to create a public website to give both internal and external users secure access to your data.

Users can create websites in the Power Apps UI with application capabilities like user authentication, forms for users to enter data, data transformation logic, storage of structured data, and APIs to retrieve that data by other applications.

On May 24, an UpGuard analyst discovered that the OData API for a Power Apps portal had accessible list data including personally identifiable information.

The owner of that application was notified and the data secured.

That case led to the question of whether there were other portals with the same situation — the combination of configurations allowing lists to be accessed anonymously via OData feed APIs, and sensitive data collected and stored by the apps.

Wired reported Microsoft has now changed the default permissions settings responsible for the exposure.

Latest

More like this
Related

IDC views on cybersecurity spending of $377 bn by 2028

Stefano Perini, research manager with IDC Data and Analytics,...

Gartner’s views on Google Cloud’s $32 bn deal to buy Wiz

Google has announced its acquisition of Wiz, a leading...

Google Cloud’s $32 bn Wiz deal explained

Alphabet has announced its largest acquisition to date with...

Infosys settles U.S. cyber incident lawsuits for $17.5 mn

Indian IT services giant Infosys has reached a settlement...