CVE-2019-0857Improper Encoding or Escaping of Output in Microsoft Azure Devops Server

Severity
6.5MEDIUMNVD
EPSS
16.4%
top 5.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 13

Description

A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6hjh-rrqc-j242: A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input,2022-05-13
CVEList
CVE-2019-0857: A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input,2019-04-09

📋Vendor Advisories

1
Microsoft
Azure DevOps Server Spoofing Vulnerability2019-04-09

💬Community

2
Bugzilla
CVE-2019-5068 mesa: security bypass in 3D library graphics2019-11-08
Bugzilla
CVE-2019-3868 keycloak: session hijack using the user access token2019-02-20
CVE-2019-0857 — Improper Encoding or Escaping of Output | cvebase