Microsoft Azure Devops Server 2019 vulnerabilities

5 known vulnerabilities affecting microsoft/azure_devops_server_2019.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2020-1326MEDIUMCVSS 5.4vUpdate 12020-07-14
CVE-2020-1326 [MEDIUM] CWE-79 CVE-2020-1326: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitiz A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
cvelistv5nvd
CVE-2020-1327MEDIUMCVSS 6.1vUpdate 12020-06-09
CVE-2020-1327 [MEDIUM] CWE-79 CVE-2020-1327: A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle we A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
cvelistv5nvd
CVE-2020-0758HIGHCVSS 7.5vUpdate 12020-03-12
CVE-2020-0758 [HIGH] CVE-2020-0758: An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.
cvelistv5
CVE-2020-0700MEDIUMCVSS 5.4vUpdate 12020-03-12
CVE-2020-0700 [MEDIUM] CWE-79 CVE-2020-0700: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitiz A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
cvelistv5nvd
CVE-2019-0996MEDIUMCVSS 6.5fixed in publication2019-06-12
CVE-2019-0996 [MEDIUM] CWE-352 CVE-2019-0996: A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to author A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application on behalf of the targeted user. To exploit this vulnerability, an attacker
cvelistv5nvd