Improper Neutralization of Special Elements in Output Used by a Downstream Component in Azure DevOps Server - CVE-2019-0869

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Azure DevOps Server - CVE-2019-0869

Published: April 9, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36012
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0869
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.


Affected software

Azure DevOps Server

How to mitigate CVE-2019-0869

Install update from vendor's website.


External References

Related Security Bulletins