First published: Tue Nov 14 2023(Updated: )
Azure DevOps Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Chocolatey Azure Pipelines Agent | <2.39.1 | |
Chocolatey Azure Pipelines Agent |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36437 is high with a severity value of 8.8.
CVE-2023-36437 is a remote code execution vulnerability that affects Azure DevOps Server.
The affected software for CVE-2023-36437 is Microsoft Azure Pipelines Agent.
To fix CVE-2023-36437, you can apply the patch provided by Microsoft or update to the latest version of Azure Pipelines Agent.
You can find more information about CVE-2023-36437 on the Microsoft Security Response Center website.