CVE-2019-0996 is a medium-severity spoofing vulnerability affecting Microsoft Azure DevOps Server. It allows an attacker to bypass OAuth protections and register an application on behalf of a targeted user through a cross-site request forgery (CSRF) attack. Exploitation requires an attacker to craft a malicious webpage and trick a user into clicking a link to it. While no public exploit code is available and it's not on the KEV catalog, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.