← Back

CVE-2020-0758

nvd nist
Published: Mar 12, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.

Affected (6)

2 products
Azure Devops Server
Team Foundation Server
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2019.0.1
Version 2019 update1.1
Version 2019 update1
Microsoft
Version 2017 update3.1
Version 2018 update1.2
Version 2018 update3.2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.