Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0647

Опубликовано: 15 янв. 2019
Источник: msrc
EPSS Средний

Описание

Team Foundation Server Information Disclosure Vulnerability

An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret. An authenticated attacker who successfully exploited this vulnerability could view variables that were hidden by other users.

To exploit the vulnerability, an authenticated attacker would need to create a task group with a task containing a secret variable.

The security update addresses the vulnerability by correcting how variables are handled.

FAQ

What version of Team Foundation Server is affected by this vulnerability?

References for Team Foundation Server 2017 Update 3Identification
Last version of Team Foundation Server 2017 Update 3 affected by this vulnerabilityVersion 3.1
First version of Team Foundation Server 2017 Update 3 with this vulnerability addressedVersion 3.1 Patch Update
References for Team Foundation Server 2018 Update 1Identification
Last version of Team Foundation Server 2018 Update 1 affected by this vulnerabilityVersion 1.2
First version of Team Foundation Server 2018 Update 1 with this vulnerability addressedVersion 1.2 Patch Update
References for Team Foundation Server 2018 Update 3Identification
Last version of Team Foundation Server 2018 Update 3 affected by this vulnerabilityVersion 3.1
First version of Team Foundation Server 2018 Update 3 with this vulnerability addressedVersion 3.2

Please see Microsoft DevOps Blog for more information.

Обновления

ПродуктСтатьяОбновление
Team Foundation Server 2017 Update 3.1
Team Foundation Server 2018 Update 1.2
Team Foundation Server 2018 Update 3.2

Показывать по

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 93%
0.10557
Средний

Связанные уязвимости

CVSS3: 6.5
nvd
около 7 лет назад

An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." This affects Team.

CVSS3: 6.5
github
больше 3 лет назад

An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." This affects Team.

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость системы управления проектами и контроля версий Microsoft Team Foundation Server, связанная с ошибками механизма защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 93%
0.10557
Средний