Vulnerabilities > Microsoft > Azure Devops Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-12 CVE-2020-0758 Improper Privilege Management vulnerability in Microsoft Azure Devops Server and Team Foundation Server
An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'.
network
microsoft CWE-269
6.0
2019-06-12 CVE-2019-0996 Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Azure Devops Server 2019
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery, aka 'Azure DevOps Server Spoofing Vulnerability'.
network
microsoft CWE-352
4.3
2019-04-09 CVE-2019-0875 Unspecified vulnerability in Microsoft Azure Devops Server 2019
An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'.
network
low complexity
microsoft
5.0
2019-04-09 CVE-2019-0874 Cross-site Scripting vulnerability in Microsoft Azure Devops Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
4.3
2019-04-09 CVE-2019-0871 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
4.3
2019-04-09 CVE-2019-0870 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
4.3
2019-04-09 CVE-2019-0869 Cross-site Scripting vulnerability in Microsoft Azure Devops Server 2019
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
network
microsoft CWE-79
4.3
2019-04-09 CVE-2019-0868 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
4.3
2019-04-09 CVE-2019-0867 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
4.3
2019-04-09 CVE-2019-0866 Cross-site Scripting vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'.
network
microsoft CWE-79
4.3