First published: Thu May 16 2019(Updated: )
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0971 is an information disclosure vulnerability in Azure DevOps Server and Microsoft Team Foundation Server.
CVE-2019-0971 has a severity of critical.
CVE-2019-0971 occurs when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request.
CVE-2019-0971 affects Microsoft Team Foundation Server 2018-3.2 and Microsoft Azure DevOps Server 2019.
To fix CVE-2019-0971, it is recommended to apply the necessary security updates provided by Microsoft.