QID 91985

Date Published: 2023-02-15

QID 91985: Azure DevOps Server Multiple Vulnerabilities for February 2023

Azure DevOps Server is a Microsoft product that provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities.
CVE-2023-21564: Azure DevOps Server Cross-Site Scripting Vulnerability.
CVE-2023-21553: Azure DevOps Server Remote Code Execution Vulnerability.

Affected Software:
Azure DevOps Server 2022.
Azure DevOps Server 2020.1.2

QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.TeamFoundation.Framework.Server.dll.

Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Customers are advised to refer to CVE-2023-21564, CVE-2023-21553, for more details.

    CVEs related to QID 91985

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-21553 URL Logo msrc.microsoft.com/update-guide//vulnerability/CVE-2023-21553
    CVE-2023-21564 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21564