First published: Thu May 16 2019(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0872.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0979 is a Cross-site Scripting (XSS) vulnerability in Azure DevOps Server and Team Foundation Server.
The vulnerability occurs when these servers do not properly sanitize user provided input, allowing attackers to inject malicious scripts into web pages viewed by other users.
Team Foundation Server versions 2017-3.1, 2018-1.2, and 2018-3.2, as well as Azure DevOps Server 2019, are affected.
The severity of CVE-2019-0979 is medium, with a CVSS score of 5.4.
To mitigate the vulnerability, it is recommended to apply the appropriate security updates provided by Microsoft and ensure that user supplied inputs are properly sanitized.