CVE-2023-36019 β Critical Christmas Gift from Microsoft Power Platform
What do I need to do? Nokod Security customers are taking the fast lane to remediation.
If you are a Nokod Security customer, sit back and relaxΒ βΒ our solutionΒ lets you know through a new type of Insight which connectors need your attention.
If you are not a Nokod Security customer, look through the list of custom connectors for those who use OAuth 2.0 authentication and are configured with Global Redirect URI.
Or, contact us atΒ [email protected], and we will help you.cessible inside an organization as well as reports that are published to the web.
CVE-2023-36019 in Detail
An attacker can exploit this vulnerability by crafting a malicious link, file, or application that appears to be a legitimate connector and tricking the victim into interacting with it. This could result in the attacker gaining access to the victimβs data, credentials, or system resources. While the vulnerability is in the web server, malicious scripts execute in the victimβs browser on his/her local machine.
Takeaways
This vulnerability highlights the importance of securing low-code/no-code applications and their components, such as custom connectors and third-party components.
Low-code/no-code apps are designed to enable users with little or no coding experience to create and deploy applications quickly and easily. However, this also means that users may not be aware of theΒ potential security risks.
While it is important to follow the security guidance and recommendations provided by Microsoft and other LCAP vendors, including applying the latest patches and updates as soon as possible β it is not enough.
It is evident from this recent incident that security teams need help in identifying vulnerable components and remediating them. Moreover, most of the security issues stem from application and flow logic and therefore do not fall under the responsibility of the LCAP vendor. It is clearly time for enterprises who (rightfully) chose the path of no-code/low-code development to deploy a dedicated security solution for LCNC AppSec.