Vulnerability Description
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability'.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Team Foundation Server | 2018 |
| Microsoft | Azure Devops Server | 2019 |
Related Weaknesses (CWE)
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0971PatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0971PatchVendor Advisory
FAQ
What is CVE-2019-0971?
CVE-2019-0971 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, ...
How severe is CVE-2019-0971?
CVE-2019-0971 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0971?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Team Foundation Server, Microsoft Azure Devops Server.