VYPR
Critical severity9.1NVD Advisory· Published Aug 13, 2024· Updated Jun 17, 2026

CVE-2024-38109

CVE-2024-38109

Description

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

Affected products

4
  • cpe:2.3:a:microsoft:azure_health_bot:-:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:azure_health_bot:-:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: N/A
  • Microsoft/Azurellm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.