CVE-2019-0875 is an elevation of privilege vulnerability affecting Azure DevOps Server 2019, stemming from improper enforcement of project permissions. This high-severity vulnerability (CVSS 7.5) can be exploited remotely without authentication, allowing an attacker to gain elevated privileges and potentially impact the integrity of data within the affected server. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.