Azure DevOps Server Spoofing Vulnerability
CVE-2024-35267

7.6HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 July 2024

Summary

A spoofing vulnerability exists in Azure DevOps Server which can allow an attacker to impersonate a legitimate user. This vulnerability could potentially facilitate unauthorized access and compromise sensitive data, making it essential for users to implement the recommended patches to safeguard their systems. Mitigating this risk requires an active response to apply security updates and monitor for any unusual activities in the environment.

Affected Version(s)

Azure DevOps Server 2022 Unknown 20231128.1 < 20240702.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.