Known vulnerabilities in Azure DevOps Server 2022
Vendor:
Microsoft
Software:
Azure DevOps Server
Version:
2022
Software CPE:
cpe:2.3:a:microsoft:azure_devops_server:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Vulnerabilities by Severity
2020 Update 1.2 Patch 19
2020 Update 1.2 Patch 18
20260204.3
2020 Update 1.2 Patch 17
2020 Update 1.2 Patch 16
2020 Update 1.2 Patch 15
2020 Update 1.2 Patch 14
2020 Update 1.2 Patch 13
2020 Update 1.2 Patch 12
2022.1
2020 Update 1.2 Patch 11
2022 Update 0.1 Patch 5
2020 Update 1.2 Patch 10
2019.0.1 Patch 16
20230927.1
20230926.2
20230926.1
2022 Update 0.1 Patch 4
2020 Update 1.2 Patch 9
20230601.3
20230825.1
20230820.2
20230823.1
20230825.4
2019.0.1 Patch 15
2022 Update 0.1 Patch 3
2020 Update 1.2 Patch 8
2019.1.2
2019.0.1 Patch 14
2019.0.1 Patch 13
2022 Update 0.1 Patch 2
2020 Update 1.2 Patch 7
2022 Update 0.1 Patch 1
2022 Patch 4
2020 Update 1.2 Patch 6
2022.0.1
2020.1.2
2022 Update 0.1
2022 Update 0.1 RC
2022 Patch 3
2022 Patch 2
2022 Patch 1
2022
2022 RC2
2022 RC1
2020.1.1 Patch 4
2020.1.1 Patch 3
2020.1.1 Patch 2
2020.1.1 Patch 1
2020.1 RTW
2020.1 RC2
2020.1 RC1
2020.1 Patch 2
2020.1 Patch 1
2020 Update 1.2 Patch 5
2020 Update 1.2 Patch 4
2020 Update 1.2 Patch 3
2020 Update 1.2 Patch 2
2020 Update 1.2 Patch 1
2020 Update 1.2
2020 Update 1.1
2019.0.1 Patch 12
2019.0.1 Patch 11
2019.0.1 Patch 10
2019.0.1 Patch 9
2019.0.1 Patch 8
2019.0.1 Patch 7
2019.0.1 Patch 6
2019.0.1 Patch 5
2020.0.1
2013
2012
2010
2018
2017
2015
2019 Update 1.1
2019.0.1 Patch 3
2019.0.1 Patch 2
2019.0.1 Patch 1
2019.0.1
2019.0.1 RC
2019 Patch 2
2019 Patch 1
2019
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU122567 - Server-Side Request Forgery (SSRF) CVE-2026-21512 |
CWE-918 | Medium | - | 10.02.2026 |
SB2026021077 |
||
| #VU77245 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2023-21565 |
CWE-451 | Medium | - | 13.06.2023 |
SB2023061359 |
||
| #VU77244 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2023-21569 |
CWE-451 | Medium | - | 13.06.2023 |
SB2023061359 |
||
| #VU72232 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-21564 |
CWE-79 | Medium | 2022 Patch 2 | 15.02.2023 |
SB2023021515 |