You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Remove the list chat bots permission from users that should not have the ability to view connection strings. Invalidate any credentials previously stored for safety.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Learn more on MITRE.
Impact
Instance users with the list chat bots permission can read chat bot connections strings without the associated permission.
Patches
#1487
Workarounds for Affected Versions
Remove the list chat bots permission from users that should not have the ability to view connection strings. Invalidate any credentials previously stored for safety.