First published: Wed Dec 09 2020(Updated: )
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual Studio Team Foundation Server | =2015-4.2 | |
Microsoft Visual Studio Team Foundation Server | =2017-3.1 | |
Microsoft Visual Studio Team Foundation Server | =2018-1.2 | |
Microsoft Visual Studio Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019-update1.1 | |
Microsoft Azure DevOps Server | =2019.0.1 | |
Microsoft Azure DevOps Server | =2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17145 has a CVSS score indicating medium severity, primarily due to a spoofing risk.
To remediate CVE-2020-17145, apply the latest security updates released by Microsoft for affected Azure DevOps Server and Team Foundation Server versions.
CVE-2020-17145 affects Microsoft Team Foundation Server 2015, 2017, 2018 and Microsoft Azure DevOps Server 2019 and 2020.
CVE-2020-17145 is classified as a spoofing vulnerability that can allow an attacker to impersonate another user.
Yes, CVE-2020-17145 can potentially be exploited remotely if an attacker can interact with the affected server.