CVE-2019-0971High
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server. An attacker who successfully exploited this vulnerability could execute malicious code on a vulnerable server. To exploit this vulnerability, an authenticated attacker would need to create a page specifically designed to cause a server-side request. The attacker would then send a specially-crafted message to perform a server-side request forgery attack. The update addresses the vulnerability by modifying how Azure DevOps Server and Microsoft Team Foundation Server manage server authentication.
🎯 Affected products2
- Azure DevOps Server 2019
- Team Foundation Server 2018 Update 3.2
✅ Remediation
KBRelease Notes (Security Update)