CVE-2019-0857
published 2019-04-09CVE-2019-0857: A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka…
PriorityP335medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
3.86%
88.9th percentile
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| msrc | azure_devops_server_2019 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hjh-rrqc-j242: A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input,
ghsa_unreviewed·2022-05-13
CVE-2019-0857 [MEDIUM] CWE-116 GHSA-6hjh-rrqc-j242: A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input,
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.
Microsoft
Azure DevOps Server Spoofing Vulnerability
vendor_msrc·2019-04-09·CVSS 6.5
CVE-2019-0857 [MEDIUM] Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Description: A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input. An attacker who exploited the vulnerability could trick a user into loading a page containing malicious content.
An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Azure DevOps Server, which would get executed in the context of the user every time a user visits the compromised page. To exploit the bypass, an attacker can leverage any external source in the script-src to embed malicious script by bypassing Content Security Policy (CSP).
The security update addresses the vulnerability by ensuring that Azure DevOps Server sanitizes user
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5068 mesa: security bypass in 3D library graphics
bugzilla·2019-11-08·CVSS 4.4
CVE-2019-5068 [MEDIUM] CVE-2019-5068 mesa: security bypass in 3D library graphics
CVE-2019-5068 mesa: security bypass in 3D library graphics
An exploitable shared memory permissions vulnerability exists in the
functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the
shared memory without any specific permissions to trigger this vulnerability.
Reference:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857
Discussion:
Created mesa tracking bugs for this issue:
Affects: fedora-all [bug 1770096]
---
Upstream bug: https://gitlab.freedesktop.org/mesa/mesa/issues/121
Upstream patch: https://gitlab.freedesktop.org/mesa/mesa/commit/ddc7d7a33b36c2305955bbffb1f295196c1a9669
---
External References:
https://www.mesa3d.org/relnotes/19.1.8.html
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857
Bugzilla
CVE-2019-3868 keycloak: session hijack using the user access token
bugzilla·2019-02-20·CVSS 3.8
CVE-2019-3868 [LOW] CVE-2019-3868 keycloak: session hijack using the user access token
CVE-2019-3868 keycloak: session hijack using the user access token
Keycloak allows end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2 for RHEL 7
Via RHSA-2019:0856 https://access.redhat.com/errata/RHSA-2019:0856
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2 for RHEL 6
Via RHSA-2019:0857 https://access.redhat.com/errata/RHSA-2019:0857
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2.7 zip
Via RHSA-2019:0868 https://access.redhat.com/errata/RHSA-2019:086
2019-04-09
Published