First published: Wed Nov 14 2018(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio Team Foundation Server | =2017-3.1 | |
Microsoft Visual Studio Team Foundation Server | =2018-1.1 | |
Microsoft Visual Studio Team Foundation Server | =2018-3.0 | |
Microsoft Visual Studio Team Foundation Server | =2018-3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8602 has been assigned a medium severity rating due to its potential for exploitation via Cross-site Scripting (XSS).
To fix CVE-2018-8602, users should upgrade their Microsoft Team Foundation Server to the latest patched version that addresses the XSS vulnerability.
CVE-2018-8602 affects Microsoft Team Foundation Server versions 2017-3.1, 2018-1.1, 2018-3.0, and 2018-3.1.
The impact of CVE-2018-8602 allows attackers to execute arbitrary JavaScript in the context of the user's session, potentially compromising sensitive information.
While the best solution is to apply the update, users can temporarily mitigate CVE-2018-8602 by restricting access to vulnerable components of Team Foundation Server.