CVE-2023-21751HighCVSS 6.5

Azure DevOps Server Spoofing Vulnerability

Published
December 13, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric,privileges required is low(PR:L). What does that mean for this vulnerability? This means that an attacker needs to have a user account in the organization with the ability to run builds.

According to the CVSS metric, successful exploitation of this vulnerability could impact the integrity(I:H). What does that mean for this vulnerability? Successful exploitation compromises the integrity of the build verification process, allowing an attacker to spoof and bypass verification.

🎯 Affected products2

  • Azure DevOps Server 2020.1.2
  • Azure DevOps Server 2022.1

✅ Remediation

KBRelease Notes (Security Update) — fixed build 20231128.1 KBRelease Notes (Security Update) — fixed build 20231127.4

🔗 References (1)