Azure DevOps Server 2019
Azure DevOps Server 2019
Third-party support for the Microsoft Azure DevOps Server 2019: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Azure DevOps Server 2019 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- azure-devops-server
- release
- 2019.0
- product Label
- Azure DevOps Server
- release Label
- 2019
- codename
- lts
- latest Version
- 2019.0.1patch16
- release Date
- 2019-03-05
- maintained
- true
- source Url
- https://endoflife.date/azure-devops-server
Lifecycle Dates
- End of Service Life
- Apr 10, 2029
- Last OEM Support
- Apr 9, 2024
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Azure DevOps Server 2019 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Azure DevOps Server 2019?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Azure DevOps Server 2019 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Azure DevOps Server 2019 Support: Frequently Asked Questions
Is the Microsoft Azure DevOps Server 2019 still supported?
Yes. The Azure DevOps Server 2019 is currently supported by Microsoft, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Microsoft Azure DevOps Server 2019 end of service life (EOSL) date?
Microsoft lists the end of service life for the Azure DevOps Server 2019 as Apr 10, 2029.
Can I keep using the Azure DevOps Server 2019 after its EOSL date?
Yes. EOSL means Microsoft stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Azure DevOps Server 2019 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Azure DevOps Server 2019
16 published CVEs affect the Microsoft Azure DevOps Server 2019, including 5 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2019-1306 | CRITICAL | 9.8 | Sep 11, 2019 | A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'. |
| CVE-2019-1072 | CRITICAL | 9.8 | Jul 15, 2019 | A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'. |
| CVE-2023-33136 | HIGH | 8.8 | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability |
| CVE-2020-0758 | HIGH | 7.5 | Mar 12, 2020 | An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815. |
| CVE-2023-38155 | HIGH | 7.0 | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability |
| CVE-2026-21512 | MEDIUM | 6.5 | Feb 10, 2026 | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2021-27067 | MEDIUM | 6.5 | Apr 13, 2021 | Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability |
| CVE-2020-17135 | MEDIUM | 6.4 | Dec 10, 2020 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2023-36869 | MEDIUM | 6.3 | Aug 8, 2023 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2020-1327 | MEDIUM | 6.1 | Jun 9, 2020 | A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. |
| CVE-2019-0874 | MEDIUM | 6.1 | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. |
| CVE-2020-17145 | MEDIUM | 5.4 | Dec 10, 2020 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
| CVE-2020-1326 | MEDIUM | 5.4 | Jul 14, 2020 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. |
| CVE-2020-0700 | MEDIUM | 5.4 | Mar 12, 2020 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. |
| CVE-2019-1305 | MEDIUM | 5.4 | Sep 11, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. |
| CVE-2019-1076 | MEDIUM | 5.4 | Jul 15, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. |