QID 91760
Date Published: 2021-04-14
QID 91760: Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability - April 2021
Azure DevOps Server and Team Foundation Server are prone to information disclosure vulnerability.
Azure DevOps Server 2020.0.1
Azure DevOps Server 2020
Azure DevOps Server 2019.0.1
Azure DevOps Server 2019 Update 1
Azure DevOps Server 2019 Update 1.1
Team Foundation Server 2018 Update 3.2
Team Foundation Server 2018 Update 1.2
Team Foundation Server 2017 Update 3.1
Team Foundation Server 2015 Update 4.2
Successful exploitation allows attacker to get access to Azure DevOps Server pipeline configuration variables and secrets.
Solution
Customers are advised to refer to CVE-2021-27067, CVE-2021-28459 for information pertaining to this vulnerability.
Vendor References
- CVE-2021-27067 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27067 - CVE-2021-28459 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28459
CVEs related to QID 91760
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Azure DevOps Server 2019 Update 1 |
|
||
| Azure DevOps Server 2019 Update 1.1 |
|
||
| Azure DevOps Server 2019.0.1 |
|
||
| Azure DevOps Server 2020 |
|
||
| Azure DevOps Server 2020.0.1 |
|
||
| Team Foundation Server 2015 Update 4.2 |
|
||
| Team Foundation Server 2017 Update 3.1 |
|
||
| Team Foundation Server 2018 Update 1.2 |
|
||
| Team Foundation Server 2018 Update 3.2 |
|