First published: Thu May 16 2019(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0979.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2015-4.2 | |
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0872 is a Cross-site Scripting (XSS) vulnerability that exists in Azure DevOps Server and Team Foundation Server.
Microsoft Team Foundation Server 2015-4.2 is affected by CVE-2019-0872, and it is vulnerable to Cross-site Scripting (XSS) attacks if user input is not properly sanitized.
Microsoft Team Foundation Server 2018-3.2 is affected by CVE-2019-0872, and it is vulnerable to Cross-site Scripting (XSS) attacks if user input is not properly sanitized.
Microsoft Azure DevOps Server 2019 is affected by CVE-2019-0872, and it is vulnerable to Cross-site Scripting (XSS) attacks if user input is not properly sanitized.
CVE-2019-0872 has a severity rating of medium, with a CVSS score of 5.4.