Vulnerabilities > Microsoft > Azure Devops Server

DATE CVE VULNERABILITY TITLE RISK
2019-06-12 CVE-2019-0996 Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Azure Devops Server 2019
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery, aka 'Azure DevOps Server Spoofing Vulnerability'.
network
low complexity
microsoft CWE-352
6.5
2019-05-16 CVE-2019-0979 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-05-16 CVE-2019-0971 Improper Encoding or Escaping of Output vulnerability in Microsoft Azure Devops Server and Team Foundation Server
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-116
6.5
2019-05-16 CVE-2019-0872 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-04-09 CVE-2019-0875 Unspecified vulnerability in Microsoft Azure Devops Server 2019
An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'.
network
low complexity
microsoft
7.5
2019-04-09 CVE-2019-0874 Cross-site Scripting vulnerability in Microsoft Azure Devops Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
network
low complexity
microsoft CWE-79
6.1
2019-04-09 CVE-2019-0871 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
low complexity
microsoft CWE-79
6.1
2019-04-09 CVE-2019-0870 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
low complexity
microsoft CWE-79
6.1
2019-04-09 CVE-2019-0869 Cross-site Scripting vulnerability in Microsoft Azure Devops Server 2019
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
network
low complexity
microsoft CWE-79
6.1
2019-04-09 CVE-2019-0868 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
low complexity
microsoft CWE-79
6.1