First published: Tue Apr 13 2021(Updated: )
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
=2015-4.2 | ||
=2017-3.1 | ||
=2018-1.2 | ||
=2018-3.2 | ||
=2019-update1 | ||
=2019-update1.1 | ||
=2019.0.1 | ||
=2020 | ||
Microsoft Team Foundation Server | =2015-4.2 | |
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019-update1 | |
Microsoft Azure DevOps Server | =2019-update1.1 | |
Microsoft Azure DevOps Server | =2019.0.1 | |
Microsoft Azure DevOps Server | =2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27067 is an information disclosure vulnerability in Azure DevOps Server and Team Foundation Server.
Azure DevOps Server versions 2015-4.2, 2017-3.1, 2018-1.2, and 2018-3.2, as well as Microsoft Azure DevOps Server versions 2019-update1, 2019-update1.1, 2019.0.1, and 2020 are affected by CVE-2021-27067.
CVE-2021-27067 has a severity rating of medium (6.5).
To fix CVE-2021-27067, users should apply the latest security updates provided by Microsoft.
You can find more information about CVE-2021-27067 on the Microsoft Security Response Center website.