Описание
Azure DevOps Server Spoofing Vulnerability
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input. An attacker who exploited the vulnerability could trick a user into loading a page containing malicious content.
An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Azure DevOps Server, which would get executed in the context of the user every time a user visits the compromised page. To exploit the bypass, an attacker can leverage any external source in the script-src to embed malicious script by bypassing Content Security Policy (CSP).
The security update addresses the vulnerability by ensuring that Azure DevOps Server sanitizes user input and enforces a strict CSP policy.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Azure DevOps Server 2019 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
EPSS
Связанные уязвимости
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.
Уязвимость набора средств разработки программного обеспечения для совместной работы Azure DevOps Server, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS