CVE Vulnerabilities

CVE-2020-0758

Published: Mar 12, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2020-0815.

Affected Software

Name Vendor Start Version End Version
Team_foundation_server Microsoft 2017-update3.1 (including) 2017-update3.1 (including)
Team_foundation_server Microsoft 2018-update1.2 (including) 2018-update1.2 (including)
Team_foundation_server Microsoft 2018-update3.2 (including) 2018-update3.2 (including)
Azure_devops_server Microsoft 2019-update1 (including) 2019-update1 (including)
Azure_devops_server Microsoft 2019-update1.1 (including) 2019-update1.1 (including)
Azure_devops_server Microsoft 2019.0.1 (including) 2019.0.1 (including)

References