Azure DevOps Server Cross-Site Scripting Vulnerability
CVE-2023-21564
7.1HIGH
What is CVE-2023-21564?
A cross-site scripting vulnerability in Azure DevOps Server allows attackers to execute malicious scripts in the context of users' browsers. This can lead to unauthorized access to sensitive information and the potential for further compromise of affected systems. Proper user input validation and output encoding measures are critical to mitigate this risk. Microsoft has provided updates to address this issue; users are encouraged to apply these patches to safeguard their environments.
Affected Version(s)
Azure DevOps Server 2022 Unknown 20230131.0 < 20230131.1