CVE-2019-0647Medium

Team Foundation Server Information Disclosure Vulnerability

Published
January 15, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret. An authenticated attacker who successfully exploited this vulnerability could view variables that were hidden by other users. To exploit the vulnerability, an authenticated attacker would need to create a task group with a task containing a secret variable. The security update addresses the vulnerability by correcting how variables are handled.

🎯 Affected products3

  • Team Foundation Server 2017 Update 3.1
  • Team Foundation Server 2018 Update 1.2
  • Team Foundation Server 2018 Update 3.2

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (4)