CVE-2023-36561

Severity
7.3HIGH
EPSS
0.3%
top 49.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10

Description

Azure DevOps Server Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages4 packages

CVEListV5microsoft/azure_devops_server_2020.0.22020.0.020230927.1
CVEListV5microsoft/azure_devops_server_2020.1.22020.1.020230926.2
CVEListV5microsoft/azure_devops_server_2022.0.12022.0.020230926.1
NVDmicrosoft/azure_devops_server2020.0.2, 2020.1.2, 2022.0.1+2

Patches

🔴Vulnerability Details

2
CVEList
Azure DevOps Server Elevation of Privilege Vulnerability2023-10-10
GHSA
GHSA-6r24-858h-vm25: Azure DevOps Server Elevation of Privilege Vulnerability2023-10-10

📋Vendor Advisories

1
Microsoft
Azure DevOps Server Elevation of Privilege Vulnerability2023-10-10
CVE-2023-36561 (HIGH CVSS 7.3) | Azure DevOps Server Elevation of Pr | cvebase.io