First published: Wed Sep 11 2019(Updated: )
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019-update1 | |
Microsoft Azure DevOps Server | =2019.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1306 refers to a remote code execution vulnerability that exists in Azure DevOps Server (ADO) and Team Foundation Server (TFS).
CVE-2019-1306 allows remote code execution when ADO and TFS fail to properly validate input.
The severity of CVE-2019-1306 is critical with a CVSS score of 9.8.
Microsoft Team Foundation Server 2018-3.2, Microsoft Azure DevOps Server 2019-update1, and Microsoft Azure DevOps Server 2019.0.1 are affected by CVE-2019-1306.
To fix CVE-2019-1306, update to the latest version of Microsoft Team Foundation Server or Microsoft Azure DevOps Server.