Severity
5.4MEDIUM
EPSS
0.8%
top 25.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 24

Description

A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

CVEListV5microsoft/team_foundation_server2017 Update 3.1
CVEListV5microsoft/team_foundation_server_2018Update 1.2, Update 3.2+1

Patches

🔴Vulnerability Details

4
GHSA
cnlh nps vulnerable to file overwrite by local user2022-05-24
GHSA
GHSA-5h3x-73w2-c5q7: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Ser2022-05-14
GHSA
netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions2019-10-14
CVEList
CVE-2019-0777: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Ser2019-04-09

📋Vendor Advisories

3
Red Hat
glib2: insecure permissions for files and directories2019-06-28
Microsoft
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir NULL NULL) and files using g_file_replace_contents (kfsb-2019-06-11
Microsoft
Team Foundation Server Cross-site Scripting Vulnerability2019-03-12

🕵️Threat Intelligence

1
Talos
Vulnerability Spotlight: Remote code execution bug in SQLite2019-05-09

💬Community

2
Bugzilla
CVE-2019-5018 sqlite: Use-after-free in window function leading to remote code execution2019-05-09
Bugzilla
CVE-2019-3881 rubygem-bundler: Insecure permissions on directory in /tmp/ allows for execution of malicious code2018-11-21
CVE-2019-0777 (MEDIUM CVSS 5.4) | A Cross-site Scripting (XSS) vulner | cvebase.io