CVE-2019-0866
Published: Apr 9, 2019
Modified: Aug 4, 2024
Description
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0867, CVE-2019-0868, CVE-2019-0870, CVE-2019-0871.
| Vendor | Product | Versions |
|---|---|---|
Microsoft | Team Foundation Server | affected 2017 Update 3.1 |
Microsoft | Team Foundation Server 2018 | affected Update 1.2affected Update 3.2 |
Microsoft | Azure DevOps Server | affected 2019 |
Microsoft | Team Foundation Server 2015 | affected Update 4.2 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now