Important EPSS 0.03858 2019-04 archive

Executive Summary

A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input. An attacker who exploited the vulnerability could trick a user into loading a page containing malicious content. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Azure DevOps Server, which would get executed in the context of the user every time a user visits the compromised page. To exploit the bypass, an attacker can leverage any external source in the script-src to embed malicious script by bypassing Content Security Policy (CSP). The security update addresses the vulnerability by ensuring that Azure DevOps Server sanitizes user input and enforces a strict CSP policy.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Spoofing
Released Apr 9 2019
Last Updated Apr 9 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.03858 — 0.88801 percentile

EPSS Score

0.03858
probability of exploitation in the next 30 days
0.88801 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Azure DevOps Server 2019 Release Notes (Security Update) Important Spoofing Maybe

Patches

1 patch
Article Type Restart
Release Notes Security Update Maybe

Known Exploits

Acknowledgments

Luật Nguyễn from MSRC V&M team