First published: Thu Jan 17 2019(Updated: )
An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." This affects Team.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0647 is an information disclosure vulnerability in Team Foundation Server.
The severity of CVE-2019-0647 is medium with a severity value of 6.5.
CVE-2019-0647 affects Team Foundation Server by allowing information disclosure when variables marked as secret are not properly handled.
CVE-2019-0647 affects Team Foundation Server 2017 (version 2017-3.1), Team Foundation Server 2018 (versions 2018-1.2 and 2018-3.2).
To fix CVE-2019-0647, Microsoft has released security updates that need to be applied to the affected versions of Team Foundation Server.