Important CVSS 6.5 EPSS 0.03858 2019-04 archive

Executive Summary

A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input. An attacker who exploited the vulnerability could trick a user into loading a page containing malicious content. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Azure DevOps Server, which would get executed in the context of the user every time a user visits the compromised page. To exploit the bypass, an attacker can leverage any external source in the script-src to embed malicious script by bypassing Content Security Policy (CSP). The security update addresses the vulnerability by ensuring that Azure DevOps Server sanitizes user input and enforces a strict CSP policy.

Overview

6.5
CVSS MEDIUM
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Spoofing
Released Apr 9 2019
Last Updated Apr 9 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.03858 — 0.89065 percentile
NVD CVSS 6.5 MEDIUM — differs from MSRC

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged

EPSS Score

0.03858
probability of exploitation in the next 30 days
0.89065 percentile - updated 2026-07-25
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Azure DevOps Server 2019 Release Notes (Security Update) Important Spoofing Maybe

Patches

1 patch
Article Type Restart
Release Notes Security Update Maybe

Known Exploits

Acknowledgments

Luật Nguyễn from MSRC V&M team