QID 92024
Date Published: 2023-06-14
QID 92024: Azure DevOps Server Spoofing Vulnerability for June 2023
Azure DevOps Server is a Microsoft product that provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities.
CVE-2023-21569: Azure DevOps Server Spoofing Vulnerability.
CVE-2023-21565: Azure DevOps Server Spoofing Vulnerability.
Affected Software:
Azure DevOps Server 2022
Azure DevOps Server 2020.1.2
Azure DevOps Server 2022.0.1
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.TeamFoundation.Framework.Server.dll.
Successful exploitation could allow spoofing vulnerability.
Solution
Customers are advised to refer to CVE-2023-21569, CVE-2023-21565, for more details.
Vendor References
- CVE-2023-21565 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21565 - CVE-2023-21569 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21569
CVEs related to QID 92024
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-21565 |
|
||
| CVE-2023-21569 |
|