Azure DevOps Server Elevation of Privilege Vulnerability
CVE-2023-36561
7.3HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 October 2023
What is CVE-2023-36561?
An elevation of privilege vulnerability exists in Azure DevOps Server, enabling an attacker to gain elevated access rights. This vulnerability could allow an attacker to perform actions that would normally be restricted, potentially leading to a compromise of system integrity. It is crucial for organizations using affected versions of Azure DevOps Server to apply security updates to mitigate risks and secure their development environments.
Affected Version(s)
Azure DevOps Server 2020.0.2 Unknown 2020.0.0 < 20230927.1
Azure DevOps Server 2020.1.2 Unknown 2020.1.0 < 20230926.2
Azure DevOps Server 2022.0.1 Unknown 2022.0.0 < 20230926.1