<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Azure DevOps Server</title>
  <link>https://cvedaily.com/pages/tags/azure-devops-server.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/azure-devops-server.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Azure DevOps Server</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-21512 – Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21512</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21512</strong></p>
  <p>Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35267 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35267</guid>
    <pubDate>Tue, 09 Jul 2024 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35267</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35266 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35266</guid>
    <pubDate>Tue, 09 Jul 2024 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35266</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20667 – Azure DevOps Server Remote Code Execution Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20667</guid>
    <pubDate>Tue, 13 Feb 2024 18:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20667</strong></p>
  <p>Azure DevOps Server Remote Code Execution Vulnerability</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-21751 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21751</guid>
    <pubDate>Thu, 14 Dec 2023 00:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-21751</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36437 – Azure DevOps Server Remote Code Execution Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36437</guid>
    <pubDate>Tue, 14 Nov 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36437</strong></p>
  <p>Azure DevOps Server Remote Code Execution Vulnerability</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36561 – Azure DevOps Server Elevation of Privilege Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36561</guid>
    <pubDate>Tue, 10 Oct 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36561</strong></p>
  <p>Azure DevOps Server Elevation of Privilege Vulnerability</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38155 – Azure DevOps Server Remote Code Execution Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38155</guid>
    <pubDate>Tue, 12 Sep 2023 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38155</strong></p>
  <p>Azure DevOps Server Remote Code Execution Vulnerability</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33136 – Azure DevOps Server Remote Code Execution Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33136</guid>
    <pubDate>Tue, 12 Sep 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33136</strong></p>
  <p>Azure DevOps Server Remote Code Execution Vulnerability</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36869 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36869</guid>
    <pubDate>Tue, 08 Aug 2023 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36869</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-21569 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21569</guid>
    <pubDate>Wed, 14 Jun 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-21569</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-21565 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21565</guid>
    <pubDate>Wed, 14 Jun 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-21565</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25722 – A credential-leak issue was discovered in related Veracode products before 2023-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25722</guid>
    <pubDate>Tue, 28 Mar 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25722</strong></p>
  <p>A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the Jenkins remote) to discover Veracode API credentials by listing the process and its arguments. Veracode Scan Jenkins Plugin…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-21553 – Azure DevOps Server Remote Code Execution Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21553</guid>
    <pubDate>Tue, 14 Feb 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-21553</strong></p>
  <p>Azure DevOps Server Remote Code Execution Vulnerability</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-21564 – Azure DevOps Server Cross-Site Scripting Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21564</guid>
    <pubDate>Tue, 14 Feb 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-21564</strong></p>
  <p>Azure DevOps Server Cross-Site Scripting Vulnerability</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28459 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28459</guid>
    <pubDate>Tue, 13 Apr 2021 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28459</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27067 – Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27067</guid>
    <pubDate>Tue, 13 Apr 2021 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27067</strong></p>
  <p>Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-17145 – Azure DevOps Server and Team Foundation Services Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-17145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-17145</guid>
    <pubDate>Thu, 10 Dec 2020 00:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-17145</strong></p>
  <p>Azure DevOps Server and Team Foundation Services Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-17135 – Azure DevOps Server Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-17135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-17135</guid>
    <pubDate>Thu, 10 Dec 2020 00:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-17135</strong></p>
  <p>Azure DevOps Server Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1325 – Azure DevOps Server and Team Foundation Services Spoofing Vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1325</guid>
    <pubDate>Wed, 11 Nov 2020 07:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1325</strong></p>
  <p>Azure DevOps Server and Team Foundation Services Spoofing Vulnerability</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1326 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1326</guid>
    <pubDate>Tue, 14 Jul 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1326</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1327 – A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1327</guid>
    <pubDate>Tue, 09 Jun 2020 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1327</strong></p>
  <p>A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-0815 – An elevation of privilege vulnerability exists when Azure DevOps Server and Team...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-0815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-0815</guid>
    <pubDate>Thu, 12 Mar 2020 16:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-0815</strong></p>
  <p>An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0758.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-0815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-0758 – An elevation of privilege vulnerability exists when Azure DevOps Server and Team...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-0758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-0758</guid>
    <pubDate>Thu, 12 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-0758</strong></p>
  <p>An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-0758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-0700 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-0700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-0700</guid>
    <pubDate>Thu, 12 Mar 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-0700</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-0700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-1306 – A remote code execution vulnerability exists when Azure DevOps Server (ADO) and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1306</guid>
    <pubDate>Wed, 11 Sep 2019 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-1306</strong></p>
  <p>A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-1072 – A remote code execution vulnerability exists when Azure DevOps Server and Team F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1072</guid>
    <pubDate>Mon, 15 Jul 2019 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-1072</strong></p>
  <p>A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0996 – A spoofing vulnerability exists in Azure DevOps Server when it improperly handle...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0996</guid>
    <pubDate>Wed, 12 Jun 2019 14:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0996</strong></p>
  <p>A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application on behalf of the targeted user. To exploit this vulnerability, an attacker would need to create a page specifically desig…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0979 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0979</guid>
    <pubDate>Thu, 16 May 2019 19:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0979</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0872.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0971 – An information disclosure vulnerability exists when Azure DevOps Server and Micr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0971</guid>
    <pubDate>Thu, 16 May 2019 19:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0971</strong></p>
  <p>An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0872 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0872</guid>
    <pubDate>Thu, 16 May 2019 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0872</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0979.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0875 – An elevation of privilege vulnerability exists when Azure DevOps Server 2019 doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0875</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0875</strong></p>
  <p>An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0874 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0874</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0874</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0871 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0871</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0871</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0870.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0870 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0870</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0870</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0871.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0869 – A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0869</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0869</strong></p>
  <p>A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0868 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0868</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0868</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0870, CVE-2019-0871.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0867 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0867</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0867</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0868, CVE-2019-0870, CVE-2019-0871.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0866 – A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0866</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0866</strong></p>
  <p>A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0867, CVE-2019-0868, CVE-2019-0870, CVE-2019-0871.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-0857 – A spoofing vulnerability that could allow a security feature bypass exists in wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0857</guid>
    <pubDate>Tue, 09 Apr 2019 21:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-0857</strong></p>
  <p>A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0857">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
