CVE-2023-33136HighCVSS 8.8

Azure DevOps Server Remote Code Execution Vulnerability

Published
September 12, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack vector is network (AV:N), attack complexity is low (AC:L), and privilege required is low (PR:L). What is the target used in the context of the remote code execution? Successful exploitation of this vulnerability requires an attacker to have Queue Build permissions on an Azure DevOps pipeline that has an overridable variable. An attacker with these permissions could perform remote code execution (RCE) by performing a malicious input injection via a runtime parameter that could be used in place of the overridable variable.

🎯 Affected products5

  • Azure DevOps Server 2019.0.1
  • Azure DevOps Server 2019.1.2
  • Azure DevOps Server 2020.0.2
  • Azure DevOps Server 2020.1.2
  • Azure DevOps Server 2022.0.1

✅ Remediation

KBRelease Notes (Security Update) — fixed build 20230820.2 KBRelease Notes (Security Update) — fixed build 20230825.1 KBRelease Notes (Security Update) — fixed build 20230823.1 KBRelease Notes (Security Update) — fixed build 20230825.4 KBRelease Notes (Security Update) — fixed build 20230601.3

🔗 References (6)