QID 92109

Date Published: 2024-02-15

QID 92109: Azure DevOps Server Security Update for Feb 2024

Azure DevOps Server is a Microsoft product that provides version control, reporting, requirements management, project management, automated builds, testing, and release management capabilities.

Affected Software:
Azure DevOps Server 2020.1.2
Azure DevOps Server 2019.1.2
Azure DevOps Server 2022.1

QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.TeamFoundation.Framework.Server.dll.

An attacker who successfully exploited this vulnerability can compromise the integrity of the build verification process, can spoof and bypass verification.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to CVE-2024-20667 for more details.

    CVEs related to QID 92109

    Software Advisories
    Advisory ID Software Component Link
    CVE-2024-20667 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-20667