This month, we are releasing fixes that impact our self-hosted product, Azure DevOps Server.
The following versions of the products have been patched. Check out the links for each version for more details.
Azure DevOps Server 2022.1 Patch 2
If you have Azure DevOps Server 2022.1, you should install Azure DevOps Server 2022.1 Patch 2.
CVE-2024-20667: Azure DevOps Server Remote Code Execution Vulnerability.
Fixing details page rendering issue on Search extension.
Fixed a bug where the disk space used by the proxy cache folder was calculated incorrectly and the folder was not cleaned up.
Verifying Installation
Run devops2022.1patch2.exe CheckInstall, devops2022.1patch2.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that it is not installed.
Azure DevOps Server 2020.1.2 Patch 12
If you have Azure DevOps Server 2020.1.2, you should install Azure DevOps Server 2020.1.2 Patch 12.
CVE-2024-20667: Azure DevOps Server Remote Code Execution Vulnerability.
Fixed a bug where the disk space used by the proxy cache folder was calculated incorrectly and the folder was not cleaned up.
Verifying Installation
Run devops2020.1.2patch12.exe CheckInstall, devops2020.1.2patch12.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that it is not installed.
Azure DevOps Server 2019.1.2 Patch 7
If you have Azure DevOps Server 2019.1.2, you should install Azure DevOps Server 2019.1.2 Patch 7.
CVE-2024-20667: Azure DevOps Server Remote Code Execution Vulnerability.
Fixed a bug where the disk space used by the proxy cache folder was calculated incorrectly and the folder was not cleaned up.
Verifying Installation
Run devops2019.1.2patch7.exe CheckInstall, devops2019.1.2patch7.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that it is not installed.
The post February patches for Azure DevOps Server appeared first on Azure DevOps Blog.