CVE-2023-21751
published 2023-12-13CVE-2023-21751: Azure DevOps Server Spoofing Vulnerability Azure DevOps Server Spoofing Vulnerability
medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.98%
58.1th percentile
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server_2020.1.2 | >= 2020.1.0 < 20231127.4 | 20231127.4 |
| microsoft | azure_devops_server_2022 | >= 20231128.1 < 20231128.1 | 20231128.1 |
| msrc | azure_devops_server_2020.1.2 | — | — |
| msrc | azure_devops_server_2022.1 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
cvelistv56.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server Spoofing Vulnerability
vendor_msrc·2023-12-12·CVSS 6.5
CVE-2023-21751 [MEDIUM] CWE-284 Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
FAQ: According to the CVSS metric,privileges required is low(PR:L). What does that mean for this vulnerability?
This means that an attacker needs to have a user account in the organization with the ability to run builds.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could impact the integrity(I:H). What does that mean for this vulnerability?
Successful exploitation compromises the integrity of the build verification process, allowing an attacker to spoof and bypass verification.
Azure DevOps: Azure DevOps
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
CVEList
Azure DevOps Server Spoofing Vulnerability
cvelistv5·2023-12-13·CVSS 6.5
CVE-2023-21751 [MEDIUM] CWE-284 Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-13
Published