First published: Tue Apr 09 2019(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure DevOps Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0874 is a Cross-site Scripting (XSS) vulnerability in Azure DevOps Server.
The vulnerability occurs when Azure DevOps Server fails to properly sanitize user-provided input, leading to a Cross-site Scripting (XSS) vulnerability.
The severity rating of CVE-2019-0874 is medium with a CVSS score of 6.1.
The Common Weakness Enumeration (CWE) ID associated with CVE-2019-0874 is CWE-79 (Cross-site Scripting).
To fix the vulnerability, it is recommended to apply the necessary security updates or patches provided by Microsoft.