CVE-2019-0869
published 2019-04-09CVE-2019-0869: A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection…
PriorityP428medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.96%
77.9th percentile
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| msrc | azure_devops_server_2019 | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc6.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server HTML Injection Vulnerability
vendor_msrc·2019-04-09·CVSS 6.1
CVE-2019-0869 [MEDIUM] Azure DevOps Server HTML Injection Vulnerability
Azure DevOps Server HTML Injection Vulnerability
Description: A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests. An attacker who successfully exploited the vulnerability could perform script or content injection attacks, and attempt to trick the user into disclosing sensitive information. An attacker could also redirect the user to a malicious website that could spoof content or the vulnerability could be used as a pivot to chain an attack with other vulnerabilities in web services.
To exploit the vulnerability, an attacker could create a popup to harvest information or present a user with a malicious link.
The security update addresses the vulnerability by ensuring that Azure DevOps Server sanitizes user inputs.
Team Foundatio
GHSA
GHSA-9cr9-mxxr-67w4: A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injectio
ghsa_unreviewed·2022-05-13
CVE-2019-0869 [MEDIUM] CWE-79 GHSA-9cr9-mxxr-67w4: A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injectio
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-09
Published