CVE-2023-21751HighCVSS 6.5
Azure DevOps Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric,privileges required is low(PR:L). What does that mean for this vulnerability? This means that an attacker needs to have a user account in the organization with the ability to run builds.
According to the CVSS metric, successful exploitation of this vulnerability could impact the integrity(I:H). What does that mean for this vulnerability? Successful exploitation compromises the integrity of the build verification process, allowing an attacker to spoof and bypass verification.
🎯 Affected products2
- Azure DevOps Server 2020.1.2
- Azure DevOps Server 2022.1
✅ Remediation
KBRelease Notes (Security Update) — fixed build 20231128.1 KBRelease Notes (Security Update) — fixed build 20231127.4