Microsoft Power Apps Exposes 38 Million Sensitive Data Records Including COVID-19 Vaccination Statuses

0
344
Microsoft

Microsoft power apps have exposed 38 million sensitive data records including COVID-19 vaccination statuses.

Sensitive data including COVID-19 vaccination statuses, social security numbers and email addresses have been exposed due to weak default configurations for Microsoft Power Apps, according to Upguard.

Upguard Research disclosed multiple data leaks exposing 38 million data records via Microsoft Power Apps portals configured to allow public access. The data leaks impacted American Airlines, Microsoft, J.B. Hunt and governments of Indiana, Maryland and New York City. Upguard first discovered the issue involving the OData API for a Power Apps portal on May 24 and submitted a vulnerability report to Microsoft on June 24.

Private data was exposed.

According to the research, the primary issue is that all data types were public when some data like personal identifying information should have been private. Misconfiguration led to some private data being surfaced.

Since its findings, the company has reached out to Microsoft and other affected portals. It submitted a vulnerability report to the Microsoft Security Resource Center on June 24, 2021. However, it notes that Microsoft did not take any serious action until after it notified some of the portals that suffered from the most severe exposures. Many of Microsoft’s own portals were also affected by the security lapse.

Since getting into action, Microsoft has now enabled table permissions by default for Power Apps portals.

It even released a tool for the Power Apps users to self-diagnose their portals. The company even notified its government cloud customers of this issue, the consequent changes of which were observed later. Microsoft Power Apps are low-code tools to design apps and create public and private websites.

Advertise on TechMoran.com — reach founders, innovators, and decision-makers

Promote your product, event, press release, or launch a report to a highly engaged tech and business audience. You can also take over our homepage for premium visibility and sponsor our monthly #TechNight events and podcasts and annual StartupEast Conference & Awards to maximize brand exposure.

Beyond reach and visibility, we have over ten years of experience in SEO-driven digital publishing and we focus on helping brands grow organic visibility through high-quality editorial backlinks and strategic content placement. We also help improve AI discoverability, ensuring your brand is more visible across emerging AI-powered search and recommendation systems.

Your campaign will also be extended across TechMoran.com, BusinessTech Magazine, CEO Weekends Magazine, and African Women Network Magazine, including their newsletters, giving you wider reach and engagement across East Africa’s leading digital audiences.

Contact Sales