QID 92109
Date Published: 2024-02-15
QID 92109: Azure DevOps Server Security Update for Feb 2024
Azure DevOps Server is a Microsoft product that provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities.
Affected Software:
Azure DevOps Server 2020.1.2
Azure DevOps Server 2019.1.2
Azure DevOps Server 2022.1
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.TeamFoundation.Framework.Server.dll.
An attacker who successfully exploited this vulnerability can compromise the integrity of the build verification process, can spoof and bypass verification.
Solution
Customers are advised to refer to CVE-2024-20667 for more details.
Vendor References
- CVE-2024-20667 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-20667
CVEs related to QID 92109
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-20667 |
|