web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / PowerApps Vulnerabilit...
Power Apps
Answered

PowerApps Vulnerabilities found during IT Security Scan

(0) ShareShare
ReportReport
Posted on by Microsoft Employee

We are a new to PowerApps.   Our company would be using PowerApps at the enterprise level.   However, during the proof of concept stage, an IT security audit was done.   There are two(2) high level vulnerabilites found.  

 

I have done  extensive research and have been unable to find a  resolution or something I could give to IT Security to address these issues.    

 

Can anyone assist me on this or have a resolution for these: 

 

1.  Session token in URL
Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.
Risk Level : Medium
Likelihood : Low
Risk: High

Findings
Security discovered the URL in the request appears to contain a session token within the query string.
Port/Protocol
443/TCP
Path
/autherror
/bundles
/sdkpreload
/webplayer/app

 

2.  Insecure Java Deserialization
Serialization is a process used by Java to convert an object into raw binary for storage or transmission. In the latter case, the serialized object is then transmitted to a listening host, de-serialized, and then executed. If the listening host does not perform proper validation on the serialized data it receives, a malicious user can exploit this behavior to execute code on the vulnerable system.
Risk Level: High
Likelihood : Medium
Risk : High
Findings
Security inserted a time-based payload into the HTTP request that would trigger a time delay if it were unsecurely deserialized using the Jackson library/API. The base HTTP request took 2029ms to execute, whereas the request containing the payload took 83591ms, indicating that the application is deserializing arbitrary objects using the Jackson library/API and is vulnerable to arbitrary code execution
Path
/bundles/App
Parameter
PowerAppsSessionId=
Library
Jackson
Json.NET

 

Any assistance is greatly appreicated.   

 

Thanks...

  • Verified answer
    v-yuxima-msft Profile Picture
    Microsoft Employee on at

    Hi @bmajor67 ,

     

    Could you please reference 

    security-model

    If you always have some confuse about it, please

    https://powerapps.microsoft.com/en-us/support/

     

    Hope this could be helpful.

     

    Best Regards.

    Yumia

  • pakefali Profile Picture
    Microsoft Employee on at

    Thank you for reporting this. I've requested internally for the teams that seem to be affected by this to take a look and confirm/validate the issue.

     

    I will let you know if there is anything else required from your side.

  • Verified answer
    CP-23071600-0 Profile Picture
    Microsoft Employee on at

    Hi bmajor67,

     

    As a standard routine, we perform security and penetration testing on our products and there are no known vulnerabilities.  We would need more information to investigate your claims.  Could you please share a session trace of the scenarios (Fiddler or other intercepting proxy) or the security audit document via our support channel (https://powerapps.microsoft.com -> Create a support ticket) or our support email alias (pamobsup at microsoft.com)?

     

    Thank you,

    Chris

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Leaderboard > Power Apps

#1
11manish Profile Picture

11manish 396 Super User 2026 Season 2

#2
Mohsin Ali Profile Picture

Mohsin Ali 323

#3
WarrenBelz Profile Picture

WarrenBelz 193 Most Valuable Professional

Last 30 days Overall leaderboard