First published: Thu Mar 12 2020(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019.0.1 | |
Microsoft Azure DevOps Server | =2019.0.1-update1 | |
Microsoft Azure DevOps Server | =2019.0.1-update1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0700 is a Cross-site Scripting (XSS) vulnerability in Azure DevOps Server.
The vulnerability in Azure DevOps Server allows for unauthenticated attackers to execute malicious scripts in a victim's browser.
Azure DevOps Server 2017 (version 3.1), Azure DevOps Server 2018 (version 1.2 and 3.2), Azure DevOps Server 2019 (version 2019.0.1, 2019.0.1-update1, 2019.0.1-update1.1) are affected by CVE-2020-0700.
The severity level of CVE-2020-0700 is medium, with a CVSS score of 5.4.
To fix the vulnerability, apply the necessary security updates provided by Microsoft.