CVE-2020-0815

Severity
7.5HIGH
EPSS
5.4%
top 9.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0758.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pg6g-7pwc-wmq6: An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure2022-05-24
CVEList
CVE-2020-0815: An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure2020-03-12

📋Vendor Advisories

1
Microsoft
Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability2020-03-10

💬Community

3
Bugzilla
CVE-2020-6805 Mozilla: Use-after-free when removing data about origins2020-03-10
Bugzilla
CVE-2020-6806 Mozilla: BodyStream::OnInputStreamReady was missing protections against state confusion2020-03-10
Bugzilla
CVE-2020-6807 Mozilla: Use-after-free in cubeb during stream destruction2020-03-10
CVE-2020-0815 (HIGH CVSS 7.5) | An elevation of privilege vulnerabi | cvebase.io