First published: Thu Mar 12 2020(Updated: )
An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2017-update3.1 | |
Microsoft Team Foundation Server | =2018-update1.2 | |
Microsoft Team Foundation Server | =2018-update3.2 | |
Microsoft Azure DevOps Server | =2019-update1 | |
Microsoft Azure DevOps Server | =2019-update1.1 | |
Microsoft Azure DevOps Server | =2019.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0758 is an elevation of privilege vulnerability that exists in Azure DevOps Server and Team Foundation Services.
CVE-2020-0758 affects Microsoft Team Foundation Server 2017 (Update 3.1), 2018 (Update 1.2 and 3.2), and Azure DevOps Server 2019 (Update 1, 1.1, and 2019.0.1).
CVE-2020-0758 has a severity rating of 7.5 (High).
To fix CVE-2020-0758, update Microsoft Team Foundation Server to the latest available version.
More information about CVE-2020-0758 can be found at the following link: [CVE-2020-0758](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0758)