U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:o:microsoft:azure_devops_server:2019.0.1:*:*:*:*:*:*:*
There are 14 matching records.
Displaying matches 1 through 14.
Vuln ID Summary CVSS Severity
CVE-2023-38155

Azure DevOps Server Remote Code Execution Vulnerability

Published: September 12, 2023; 1:15:19 PM -0400
V3.1: 8.1 HIGH
V2.0:(not available)
CVE-2023-33136

Azure DevOps Server Remote Code Execution Vulnerability

Published: September 12, 2023; 1:15:09 PM -0400
V3.1: 8.8 HIGH
V2.0:(not available)
CVE-2023-36869

Azure DevOps Server Spoofing Vulnerability

Published: August 08, 2023; 2:15:14 PM -0400
V3.1: 6.3 MEDIUM
V2.0:(not available)
CVE-2021-27067

Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability

Published: April 13, 2021; 4:15:15 PM -0400
V3.1: 6.5 MEDIUM
V2.0: 4.0 MEDIUM
CVE-2020-17145

Azure DevOps Server and Team Foundation Services Spoofing Vulnerability

Published: December 09, 2020; 7:15:16 PM -0500
V3.1: 5.4 MEDIUM
V2.0: 4.9 MEDIUM
CVE-2020-17135

Azure DevOps Server Spoofing Vulnerability

Published: December 09, 2020; 7:15:15 PM -0500
V3.1: 6.4 MEDIUM
V2.0: 4.9 MEDIUM
CVE-2020-1326

A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.

Published: July 14, 2020; 7:15:12 PM -0400
V3.1: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2020-1327

A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.

Published: June 09, 2020; 4:15:21 PM -0400
V3.1: 6.1 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2020-0758

An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.

Published: March 12, 2020; 12:15:13 PM -0400
V3.1: 7.5 HIGH
V2.0: 6.0 MEDIUM
CVE-2020-0700

A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.

Published: March 12, 2020; 12:15:13 PM -0400
V3.1: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2019-1306

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

Published: September 11, 2019; 6:15:19 PM -0400
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2019-1305

A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.

Published: September 11, 2019; 6:15:19 PM -0400
V3.1: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2019-1076

A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.

Published: July 15, 2019; 3:15:17 PM -0400
V3.0: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2019-1072

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

Published: July 15, 2019; 3:15:17 PM -0400
V3.0: 9.8 CRITICAL
V2.0: 7.5 HIGH