Azure DevOps Server Spoofing Vulnerability
CVE-2024-35266

7.6HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 July 2024

Summary

The Azure DevOps Server spoofing vulnerability presents significant security risks that can allow an attacker to deceive users or systems into believing they are interacting with a legitimate instance of the software. This type of vulnerability can lead to unauthorized access, data manipulation, or disruption of services. It is crucial for organizations utilizing Azure DevOps Server to implement the recommended security measures and patches to mitigate risks associated with CVE-2024-35266. Regular monitoring and adherence to best security practices are essential to protect sensitive development environments from exploitation.

Affected Version(s)

Azure DevOps Server 2022 Unknown 20231128.1 < 20240702.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.