CVE-2019-0857 — Azure DevOps Server Spoofing Vulnerability
Executive Summary
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input. An attacker who exploited the vulnerability could trick a user into loading a page containing malicious content. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Azure DevOps Server, which would get executed in the context of the user every time a user visits the compromised page. To exploit the bypass, an attacker can leverage any external source in the script-src to embed malicious script by bypassing Content Security Policy (CSP). The security update addresses the vulnerability by ensuring that Azure DevOps Server sanitizes user input and enforces a strict CSP policy.
Overview
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Azure DevOps Server 2019 | Release Notes (Security Update) |
Important | Spoofing | Maybe |
Patches
| Article | Type | Restart |
|---|---|---|
Release Notes |
Security Update | Maybe |
Known Exploits
Acknowledgments
Luật Nguyễn from MSRC V&M team