CVE-2019-0647Medium
Team Foundation Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret. An authenticated attacker who successfully exploited this vulnerability could view variables that were hidden by other users. To exploit the vulnerability, an authenticated attacker would need to create a task group with a task containing a secret variable. The security update addresses the vulnerability by correcting how variables are handled.
🎯 Affected products3
- Team Foundation Server 2017 Update 3.1
- Team Foundation Server 2018 Update 1.2
- Team Foundation Server 2018 Update 3.2
✅ Remediation
KBRelease Notes (Security Update)