CVE-2023-21564
published 2023-02-14CVE-2023-21564: Azure DevOps Server Cross-Site Scripting Vulnerability
PriorityP432high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.89%
55.1th percentile
Azure DevOps Server Cross-Site Scripting Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server_2022 | >= 20230131.0 < 20230131.1 | 20230131.1 |
| msrc | azure_devops_server_2022 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server Cross-Site Scripting Vulnerability
vendor_msrc·2023-02-14·CVSS 7.1
CVE-2023-21564 [HIGH] CWE-79 Azure DevOps Server Cross-Site Scripting Vulnerability
Azure DevOps Server Cross-Site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to no loss of availability (A:N)? What does that mean for this vulnerability?
An attacker cannot impact the availability of the service.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability?
An attacker who successfully exploited the vulnerability could access data that is available for the current user. Depending on the user's authorization the attacker could collect detailed data about ADO elements such as org/proj configuration, users, groups, teams, projects, pipelines, board, or wiki. An attacker could also craft page
GHSA
GHSA-fvm6-3mw8-9cq2: Azure DevOps Server Cross-Site Scripting Vulnerability
ghsa_unreviewed·2023-02-14
CVE-2023-21564 [HIGH] CWE-79 GHSA-fvm6-3mw8-9cq2: Azure DevOps Server Cross-Site Scripting Vulnerability
Azure DevOps Server Cross-Site Scripting Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published