Lucene search

K
cve[email protected]CVE-2019-0857
HistoryApr 09, 2019 - 9:29 p.m.

CVE-2019-0857

2019-04-0921:29:02
CWE-116
web.nvd.nist.gov
70
cve-2019-0857
spoofing vulnerability
security feature bypass
azure devops server
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.3%

A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka ‘Azure DevOps Server Spoofing Vulnerability’.

Affected configurations

Vulners
NVD
Node
microsoftazure_devops_serverMatch2019
VendorProductVersionCPE
microsoftazure_devops_server2019cpe:2.3:a:microsoft:azure_devops_server:2019:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Azure DevOps Server",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2019"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.3%