CVE-2025-29813

[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Configurations

No configuration.

History

13 May 2025, 17:15

Type Values Removed Values Added
Summary (en) An elevation of privilege vulnerability exists when Visual Studio improperly handles pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project. To exploit this vulnerability, an attacker would first have to have access to the project and swap the short-term token for a long-term one. The update addresses the vulnerability by correcting how the Visual Studio updater handles these tokens. (en) [Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de elevación de privilegios cuando Visual Studio gestiona incorrectamente los tokens de trabajo de la canalización. Un atacante que aproveche esta vulnerabilidad podría ampliar su acceso a un proyecto. Para explotarla, primero tendría que tener acceso al proyecto e intercambiar el token de corto plazo por uno de largo plazo. La actualización soluciona la vulnerabilidad corrigiendo la forma en que el actualizador de Visual Studio gestiona estos tokens.

08 May 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-08 23:15

Updated : 2025-05-13 17:15


NVD link : CVE-2025-29813

Mitre link : CVE-2025-29813

CVE.ORG link : CVE-2025-29813


JSON object : View

Products Affected

No product.

CWE
CWE-302

Authentication Bypass by Assumed-Immutable Data