Azure DevOps Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack vector is network (AV:N), attack complexity is low (AC:L), and privilege required is low (PR:L). What is the target used in the context of the remote code execution? Successful exploitation of this vulnerability requires an attacker to have Queue Build permissions on an Azure DevOps pipeline that has an overridable variable. An attacker with these permissions could perform remote code execution (RCE) by performing a malicious input injection via a runtime parameter that could be used in place of the overridable variable.
🎯 Affected products5
- Azure DevOps Server 2019.0.1
- Azure DevOps Server 2019.1.2
- Azure DevOps Server 2020.0.2
- Azure DevOps Server 2020.1.2
- Azure DevOps Server 2022.0.1
✅ Remediation
KBRelease Notes (Security Update) — fixed build 20230820.2 KBRelease Notes (Security Update) — fixed build 20230825.1 KBRelease Notes (Security Update) — fixed build 20230823.1 KBRelease Notes (Security Update) — fixed build 20230825.4 KBRelease Notes (Security Update) — fixed build 20230601.3
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33136
- referencehttps://learn.microsoft.com/en-us/azure/devops/server/release-notes/azuredevops2020?view=azure-devops
- referencehttps://learn.microsoft.com/en-us/azure/devops/server/release-notes/azuredevops2019u1?view=azure-devops
- referencehttps://learn.microsoft.com/en-us/azure/devops/server/release-notes/azuredevops2020u1?view=azure-devops
- referencehttps://learn.microsoft.com/azure/devops/server/release-notes/azuredevops2022?view=azure-devops
- referencehttps://learn.microsoft.com/en-us/azure/devops/server/release-notes/azuredevops2019?view=azure-devops