First published: Tue Jul 14 2020(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure DevOps Server | =2019-update1 | |
Microsoft Azure DevOps Server | =2019-update1.1 | |
Microsoft Azure DevOps Server | =2019.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1326 is a Cross-site Scripting (XSS) vulnerability in Azure DevOps Server.
The vulnerability occurs due to improper sanitization of user provided input in Azure DevOps Server.
The severity of CVE-2020-1326 is medium, with a CVSS score of 5.4.
Azure DevOps Server 2019, specifically versions 2019-update1, 2019-update1.1, and 2019.0.1, are affected by CVE-2020-1326.
To fix the vulnerability, update Azure DevOps Server to a version that includes the patched security update.