CVE-2023-21565
published 2023-06-13CVE-2023-21565: Azure DevOps Server Spoofing Vulnerability Azure DevOps Server Spoofing Vulnerability
high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.93%
56.7th percentile
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server_2020.1.2 | >= 2020.1.0 < 20230601.3 | 20230601.3 |
| microsoft | azure_devops_server_2022 | >= 20230131.0 < 20230602.4 | 20230602.4 |
| microsoft | azure_devops_server_2022.0.1 | >= 2022.0.0 < 20230602.5 | 20230602.5 |
| msrc | azure_devops_server_2020.1.2 | — | — |
| msrc | azure_devops_server_2022 | — | — |
| msrc | azure_devops_server_2022.0.1 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
cvelistv57.1HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server Spoofing Vulnerability
vendor_msrc·2023-06-13·CVSS 7.1
CVE-2023-21565 [HIGH] CWE-79 Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to no loss of availability (A:N)? What does that mean for this vulnerability?
An attacker cannot impact the availability of the service.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability?
An attacker who successfully exploited the vulnerability could access data that is available for the current user. Dep
CVEList
Azure DevOps Server Spoofing Vulnerability
cvelistv5·2023-06-13·CVSS 7.1
CVE-2023-21565 [HIGH] CWE-79 Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-13
Published