CVE-2020-17145
published 2020-12-10CVE-2020-17145: Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.39%
69.2th percentile
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server_2019.0.1 | >= 2019.0.0 < publication | publication |
| microsoft | azure_devops_server_2019_update_1.1 | >= 1.0 < publication | publication |
| microsoft | azure_devops_server_2020 | >= 2020 < publication | publication |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server | — | — |
| microsoft | team_foundation_server_2015_update_4.2 | >= 4.0 < publication | publication |
| microsoft | team_foundation_server_2017_update_3.1 | >= 3.0 < publication | publication |
| microsoft | team_foundation_server_2018_update_1.2 | >= 1.0 < publication | publication |
| microsoft | team_foundation_server_2018_update_3.2 | >= 3.0 < publication | publication |
| msrc | azure_devops_server_2019.0.1 | — | — |
| msrc | azure_devops_server_2019_update_1.1 | — | — |
| msrc | azure_devops_server_2020 | — | — |
| msrc | team_foundation_server_2015_update_4.2 | — | — |
| msrc | team_foundation_server_2017_update_3.1 | — | — |
| msrc | team_foundation_server_2018_update_1.2 | — | — |
| msrc | team_foundation_server_2018_update_3.2 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
vendor_msrc·2020-12-08·CVSS 5.4
CVE-2020-17145 [MEDIUM] Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Azure DevOps: Azure DevOps
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://aka.ms/azdev2019.0.1patch
Reference: https://docs.microsoft.com/en-us/azure/devops/server/release-notes/azuredevops2019?view=azure-devops
Reference: https://aka.ms/tfs2017.3.1patch
Reference: https://docs.microsoft.com/en-us/visualstudio/releasenotes/tfs2017-update3
Reference: https://aka.ms/tfs2018.1.2patch
Reference: https://docs.microsoft.com/en-us/visualstudio/releasenotes/tfs2018-update1
Reference: https://aka.ms/tfs2
GHSA
GHSA-8frx-3j37-5wj8: , aka 'Azure DevOps Server and Team Foundation Services Spoofing Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2020-17145 [MEDIUM] CWE-20 GHSA-8frx-3j37-5wj8: , aka 'Azure DevOps Server and Team Foundation Services Spoofing Vulnerability'
, aka 'Azure DevOps Server and Team Foundation Services Spoofing Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-10
Published