VDB
CVE-2023-21565
CVE-2023-21565
PUBLISHED
In Microsoft Azure DevOps Server existieren mehrere Schwachstellen. Die Fehler bestehen durch mögliche Spoofing-Angriffe, sind aber noch nicht im Detail beschrieben. Ein entfernter, authentisierter Angreifer kann diese Schwachstellen ausnutzen, um Informationen falsch darzustellen und Daten zu manipulieren. Das erfolgreiche Ausnutzen einer dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 1.85% · 83.3th percentile
Risk Scores
EPSS Score
1.85%
83.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft NuGet 6.6.0 | |
| Microsoft | Microsoft Visual Studio 2017 version 15.9 | |
| Microsoft | Microsoft .NET Framework 3.5.1 | |
| Microsoft | Microsoft NuGet 6.5.0 | |
| Microsoft | Microsoft Visual Studio 2022 version 17.5 | |
| Ubuntu | Ubuntu Linux | |
| Microsoft | Microsoft NuGet 6.2.3 | |
| Microsoft | Microsoft NuGet 6.0.4 | |
| Microsoft | Microsoft .NET Framework 4.7.1 | |
| Microsoft | Microsoft .NET Framework 4.7 | |
| Oracle | Oracle Linux | |
| Red Hat | Red Hat Enterprise Linux | |
| Microsoft | Microsoft Azure DevOps Server 2022.0.1 | |
| Microsoft | Microsoft Visual Studio 2022 version 17.6 | |
| Microsoft | Microsoft .NET Framework 4.6.2 | |
| Microsoft | Microsoft Azure DevOps Server 2022 | |
| Microsoft | Microsoft Visual Studio 2022 version 17.4 | |
| Microsoft | Microsoft Azure DevOps Server 2020.1.2 | |
| Microsoft | Microsoft .NET Framework 2.0 SP2 | |
| Microsoft | Microsoft .NET Framework 3.5 |
…and 13 more
Timeline
- Jun 13, 2023 CVE Published
- Jun 14, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Aug 24, 2023 EPSS Score
- Sep 28, 2023 EPSS Score
- Dec 8, 2023 EPSS Score
- Jan 13, 2024 EPSS Score
- Feb 17, 2024 EPSS Score
- Mar 24, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- Jun 3, 2024 EPSS Score
- Jul 8, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1446.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1446 advisory
- https://www.hitachi.com/products/it/storage-solutions/sec_info/2023/06.html advisory
- https://access.redhat.com/errata/RHSA-2023:4449 advisory
- https://access.redhat.com/errata/RHSA-2023:4448 advisory
- https://ubuntu.com/security/notices/USN-6161-2 advisory
- https://linux.oracle.com/errata/ELSA-2023-3592.html advisory
- https://linux.oracle.com/errata/ELSA-2023-3593.html advisory
- https://linux.oracle.com/errata/ELSA-2023-3582.html advisory
- http://linux.oracle.com/errata/ELSA-2023-3581.html advisory
- https://access.redhat.com/errata/RHSA-2023:3593 advisory
- https://access.redhat.com/errata/RHSA-2023:3581 advisory
- https://access.redhat.com/errata/RHSA-2023:3580 advisory
- https://access.redhat.com/errata/RHSA-2023:3582 advisory
- https://access.redhat.com/errata/RHSA-2023:3592 advisory
- https://ubuntu.com/security/notices/USN-6161-1 advisory
- https://msrc.microsoft.com/update-guide advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1448.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1448 advisory