Known Vulnerabilities for Team Foundation Server by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Team Foundation Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-27067 json | Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | 6.5 - MEDIUM | 2021-04-13 | 2023-12-29 |
| CVE-2020-17145 json | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | 5.4 - MEDIUM | 2020-12-10 | 2023-12-31 |
| CVE-2020-0758 json | An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeli... | 7.5 - HIGH | 2020-03-12 | 2021-07-21 |
| CVE-2020-0700 json | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, ak... | 5.4 - MEDIUM | 2020-03-12 | 2020-07-15 |
| CVE-2019-1306 json | A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate... | 9.8 - CRITICAL | 2019-09-11 | 2020-07-15 |
| CVE-2019-1305 json | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input,... | 5.4 - MEDIUM | 2019-09-11 | 2019-09-13 |
| CVE-2019-1076 json | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input,... | 5.4 - MEDIUM | 2019-07-15 | 2019-07-18 |
| CVE-2019-1072 json | A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user... | 9.8 - CRITICAL | 2019-07-15 | 2019-07-19 |
| CVE-2019-0979 json | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitiz... | 5.4 - MEDIUM | 2019-05-16 | 2019-07-16 |
| CVE-2019-0971 json | An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly ... | 6.5 - MEDIUM | 2019-05-16 | 2020-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Team Foundation Server | 2018 | |||
| Application | Microsoft | Team Foundation Server | 2018 | |||
| Application | Microsoft | Team Foundation Server | 2018 | |||
| Application | Microsoft | Team Foundation Server | 2018 | |||
| Application | Microsoft | Team Foundation Server | 2018 | |||
| Application | Microsoft | Team Foundation Server | 2017 | |||
| Application | Microsoft | Team Foundation Server | 2017 | |||
| Application | Microsoft | Team Foundation Server | 2015 |