Improper Neutralization of Special Elements in Output Used by a Downstream Component in Azure DevOps Server - CVE-2019-0869
Published: April 9, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU36012
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0869
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
Affected software
Azure DevOps Server
How to mitigate CVE-2019-0869
Install update from vendor's website.