CVE-2019-0857 is a spoofing vulnerability in Azure DevOps Server that allows for a security feature bypass due to improper sanitization of user-provided input. With a CVSS score of 6.5 (Medium), this vulnerability can be exploited remotely with low attack complexity, requiring user interaction, and could lead to high integrity impact. While it has a relatively low EPSS score and is not on the KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.