Azure DevOps Server Remote Code Execution Vulnerability
CVE-2023-38155

7HIGH

Key Information:

Summary

A severe vulnerability has been identified in Azure DevOps Server, allowing unauthorized users to execute arbitrary code remotely. This issue arises due to improper validation of user input. An attacker exploiting this vulnerability can gain control of affected systems, potentially leading to data breaches or service disruptions. It is crucial for users of affected versions to apply patches and take preventive measures to mitigate such risks.

Affected Version(s)

Azure DevOps Server 2019.0.1 Unknown 2019.0.0 < 20230601.3

Azure DevOps Server 2020.0.2 Unknown 2020.0.0 < 20230820.2

Azure DevOps Server 2020.1.2 Unknown 2020.1.0 < 20230823.1

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.