Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37173 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. |
Tue, 31 Dec 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Mon, 12 Aug 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:copilot_studio:-:*:*:*:*:*:*:* |
Wed, 07 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Aug 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | |
| Title | Microsoft Copilot Studio Information Disclosure Vulnerability | |
| First Time appeared |
Microsoft
Microsoft copilot Studio |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:microsoft:copilot_studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft copilot Studio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-07-10T16:33:49.936Z
Reserved: 2024-06-11T22:36:08.222Z
Link: CVE-2024-38206
Updated: 2024-08-07T14:11:52.490Z
Status : Modified
Published: 2024-08-06T22:15:54.430
Modified: 2024-08-14T00:15:08.213
Link: CVE-2024-38206
No data.
OpenCVE Enrichment
No data.
EUVD