Input validation error in Azure DevOps Server - CVE-2019-0857

 

Input validation error in Azure DevOps Server - CVE-2019-0857

Published: April 9, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36008
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0857
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.


Affected software

Azure DevOps Server

How to mitigate CVE-2019-0857

Install update from vendor's website.


External References

Related Security Bulletins