PT-2019-2256 · Microsoft · Team Foundation Server+1
Paolo Giai Polict
·
Published
2019-05-14
·
Updated
2020-08-24
·
CVE-2019-0971
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Azure DevOps Server and Microsoft Team Foundation Server (affected versions not specified)
Description
The issue is related to an information disclosure vulnerability. It occurs when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server. This vulnerability may allow a remote attacker to execute arbitrary code and impact the confidentiality, integrity, and availability of protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azure Devops Server
Team Foundation Server