CVE Vulnerabilities

CVE-2025-29813

Authentication Bypass by Assumed-Immutable Data

Published: May 08, 2025 | Modified: Jun 05, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Weakness

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

Affected Software

NameVendorStart VersionEnd Version
Azure_devopsMicrosoft- (including)- (including)

Potential Mitigations

References