First published: Wed Jun 12 2019(Updated: )
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery, aka 'Azure DevOps Server Spoofing Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure DevOps Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0996 is a spoofing vulnerability that exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery.
CVE-2019-0996 has a severity rating of 6.5, which is considered medium.
Microsoft Azure DevOps Server 2019 is affected by CVE-2019-0996.
To fix CVE-2019-0996, it is recommended to apply the necessary security updates provided by Microsoft.
You can find more information about CVE-2019-0996 on the Microsoft Security Guidance advisory page: [link](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0996).