First published: Tue Apr 09 2019(Updated: )
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0777 is a Cross-site Scripting (XSS) vulnerability that exists in Team Foundation Server when it does not properly sanitize user provided input.
CVE-2019-0777 has a severity rating of 5.4, which is considered medium.
The affected software versions are Microsoft Team Foundation Server 2017 (3.1), Microsoft Team Foundation Server 2018 (1.2), and Microsoft Team Foundation Server 2018 (3.2).
To fix CVE-2019-0777, it is recommended to apply the latest security updates provided by Microsoft.
You can find more information about CVE-2019-0777 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0777