CVE-2020-1327
Estado: ModificadaMedia (6.1)—
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.82%
- Percentil entre todas las CVEs puntuadas: 78
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-1327",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "Microsoft",
"product": "Azure DevOps Server",
"versions": [
{
"status": "affected",
"version": "2019.0.1"
}
]
},
{
"vendor": "Microsoft",
"product": "Azure DevOps Server 2019",
"versions": [
{
"status": "affected",
"version": "Update 1"
}
]
},
{
"vendor": "Microsoft",
"product": "Azure DevOps Server 2019 Update 1.1",
"versions": [
{
"status": "affected",
"version": "unspecified"
}
]
}
]
}
],
"published": "2020-06-09T20:15:21.537",
"references": [
{
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1327",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1327",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de suplantación de identidad en Microsoft Azure DevOps Server cuando presenta un fallo al manejar apropiadamente las peticiones web, también se conoce como \"Azure DevOps Server HTML Injection Vulnerability\""
}
],
"lastModified": "2026-06-17T03:01:07.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:azure_devops_server:2019:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68601DE4-2392-42CD-8A89-720BDF100230"
},
{
"criteria": "cpe:2.3:o:microsoft:azure_devops_server:2019:update1.1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0D91002-8F6D-4F58-BA1C-0806E12CA6CE"
},
{
"criteria": "cpe:2.3:o:microsoft:azure_devops_server:2019.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE7EFADB-24D4-4DB7-A9E5-9C93F1286232"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@microsoft.com"
}