CVE-2022-23254HighCVSS 4.9
Microsoft Power BI Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What actions do I need to take to be protected from this vulnerability? The main update will be automatically pushed to all affected products and services. We recommend that customers update PowerBI Client JS SDK to version 2.19.1. The package can be downloaded from NPM or NuGet Gallery. How do I know if I am affected? Our team will contact customers that are affected by this vulnerability. We recommend that affected customers save their Power Apps to ensure the fix takes effect as expected.
🎯 Affected products1
- PowerBI-client JS SDK
✅ Remediation
KBRelease Notes (Security Update) — fixed build 2.19.1