Azure DevOps Server Elevation of Privilege Vulnerability
CVE-2023-36561
7.3HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 October 2023
Summary
An elevation of privilege vulnerability exists in Azure DevOps Server, enabling an attacker to gain elevated access rights. This vulnerability could allow an attacker to perform actions that would normally be restricted, potentially leading to a compromise of system integrity. It is crucial for organizations using affected versions of Azure DevOps Server to apply security updates to mitigate risks and secure their development environments.
Affected Version(s)
Azure DevOps Server 2020.0.2 Unknown 2020.0.0 < 20230927.1
Azure DevOps Server 2020.1.2 Unknown 2020.1.0 < 20230926.2
Azure DevOps Server 2022.0.1 Unknown 2022.0.0 < 20230926.1
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved