CVE-2019-0875High

Azure DevOps Server Elevation of Privilege Vulnerability

Published
April 9, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions. An attacker who exploited the vulnerabilty could add GitHub repos to a project without having the proper access granted to their account. To exploit the vulnerability, an attacker with access to a project would need to send a specially crafted request to an affected Azure DevOps Server. The update addresses the vulnerability by correcting the way Azure DevOps Server handles project permissions.

🎯 Affected products1

  • Azure DevOps Server 2019

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)