CVE-2019-0971

CWE-1166 documents6 sources
Severity
6.5MEDIUM
EPSS
10.1%
top 6.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 24

Description

An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-858j-7757-pwv6: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially craf2022-05-24
CVEList
CVE-2019-0971: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially craf2019-05-16

📋Vendor Advisories

1
Microsoft
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability2019-05-14

🕵️Threat Intelligence

1
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in NVIDIA driver2020-06-24

💬Community

1
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-61162019-02-07
CVE-2019-0971 (MEDIUM CVSS 6.5) | An information disclosure vulnerabi | cvebase.io