PT-2025-1038 · Microsoft · Purview
Published
2025-01-09
·
Updated
2025-03-24
·
CVE-2025-21385
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
A Server-Side Request Forgery (SSRF) issue exists in Microsoft Purview, allowing an authorized attacker to disclose information over a network.
The affected software is Microsoft Purview, but the specific versions are not mentioned in the provided text.
An exploit for this issue is available, with example code found at https://t.co/pjZlXNplRN.
Further information can be found at https://t.co/zO5JzPHB8q, https://t.co/wkgoebgdM5, https://t.co/zMWGsauC2v, https://t.co/1uOrgMTikk, https://t.co/uLzNFNtlMA, and https://t.co/bfAapg51kw.
#MicrosoftPurview #SSRF #ServerSideRequestForgery #Microsoft #Cybersecurity
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Purview