Information Disclosure Vulnerability in Azure DevOps Server and Team Foundation Server
CVE-2019-0971
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 16 May 2019
What is CVE-2019-0971?
An information disclosure vulnerability exists in Azure DevOps Server and Microsoft Team Foundation Server when they fail to properly sanitize a specially crafted authentication request. This flaw could allow an attacker to gain access to sensitive information by leveraging the vulnerability in the affected servers. Proper sanitization processes are crucial to ensuring the integrity and confidentiality of authentication processes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Azure DevOps Server 2019
Team Foundation Server 2018 Update 3.2
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved