Msrc Team Foundation Server 2018 Update 3.2 vulnerabilities
21 known vulnerabilities affecting msrc/team_foundation_server_2018_update_3.2.
Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM3LOW1
Vulnerabilities
Page 1 of 2
CVE-2021-27067MEDIUMCVSS 6.52021-04-13
CVE-2021-27067 [MEDIUM] Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Azure DevOps Server pipeline configuration variables and secrets.
Azure DevOps: Azure DevOps
Microsoft: Microsoft
Impact: In
msrc
CVE-2020-17145MEDIUMCVSS 5.42020-12-08
CVE-2020-17145 [MEDIUM] Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Azure DevOps: Azure DevOps
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://aka.ms/azdev2019.0.1patch
Reference
msrc
CVE-2020-0700HIGHCVSS 5.42020-03-10
CVE-2020-0700 [MEDIUM] Azure DevOps Server Cross-site Scripting Vulnerability
Azure DevOps Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised page.
The
msrc
CVE-2020-0758HIGHCVSS 7.52020-03-10
CVE-2020-0758 [HIGH] Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability
Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project.
To exploit this vulnerability, an attacker would first
msrc
CVE-2019-1306CRITICALCVSS 9.82019-09-10
CVE-2019-1306 [CRITICAL] Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability
Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly. An attacker who successfully exploited this vulnerability could execute code on the server in the context of the TFS or ADO service account.
To exploit the vulnerabili
msrc
CVE-2019-1305HIGHCVSS 5.42019-09-10
CVE-2019-1305 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised p
msrc
CVE-2019-1072CRITICALCVSS 9.82019-07-09
CVE-2019-1072 [CRITICAL] Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability
Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input. An attacker who successfully exploited the vulnerability could execute code on the target server in the context of the DevOps or TFS service account.
To exploit t
msrc
CVE-2019-1076HIGHCVSS 5.42019-07-09
CVE-2019-1076 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised p
msrc
CVE-2019-0979HIGHCVSS 5.42019-05-14
CVE-2019-0979 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0971HIGHCVSS 6.52019-05-14
CVE-2019-0971 [MEDIUM] Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server. An attacker who successfully exploited this vulnerability could execute malicious code on a vul
msrc
CVE-2019-0872HIGHCVSS 5.42019-05-14
CVE-2019-0872 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0868HIGHCVSS 6.12019-04-09
CVE-2019-0868 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0870HIGHCVSS 6.12019-04-09
CVE-2019-0870 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0871HIGHCVSS 6.12019-04-09
CVE-2019-0871 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0866HIGHCVSS 6.12019-04-09
CVE-2019-0866 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0867HIGHCVSS 6.12019-04-09
CVE-2019-0867 [MEDIUM] Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to an Azure DevOps server or a Team Foundation server,
msrc
CVE-2019-0777LOWCVSS 5.42019-03-12
CVE-2019-0777 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised p
msrc
CVE-2019-0742HIGHCVSS 5.42019-02-12
CVE-2019-0742 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised p
msrc
CVE-2019-0743HIGHCVSS 5.42019-02-12
CVE-2019-0743 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised p
msrc
CVE-2019-0646HIGHCVSS 5.42019-01-08
CVE-2019-0646 [MEDIUM] Team Foundation Server Cross-site Scripting Vulnerability
Team Foundation Server Cross-site Scripting Vulnerability
Description: A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input. An authenticated attacker could exploit the vulnerability by sending a specially crafted payload to the Team Foundation Server, which will get executed in the context of the user every time a user visits the compromised p
msrc
1 / 2Next →