6.5

CVE-2026-21512

Azure DevOps Server Cross-Site Scripting Vulnerability

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftAzure Devops Server Version < 2022.2.0
MicrosoftAzure Devops Server Version2022.2.0 Update-
MicrosoftAzure Devops Server Version2022.2.0 Updatepatch2
MicrosoftAzure Devops Server Version2022.2.0 Updatepatch3
MicrosoftAzure Devops Server Version2022.2.0 Updatepatch4
MicrosoftAzure Devops Server Version2022.2.0 Updatepatch5
MicrosoftAzure Devops Server Version2022.2.0 Updatepatch6
MicrosoftAzure Devops Server Version2022.2.0 Updatepatch7
MicrosoftAzure Devops Server Version2022.2.0 Updaterc
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.282
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
secure@microsoft.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.