CVE-2020-17135: Azure DevOps Server Spoofing Vulnerability

Overview

Severity
Medium (CVSS 6.4)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Dec
Released
2020-12-08
EPSS Score
0.52% (percentile: 66.9%)

Affected Products (2)

Developer Tools

  • Azure DevOps Server 2019 Update 1.1
  • Azure DevOps Server 2019.0.1

Security Updates (2)

Acknowledgments

Pham Van Khanh (<a href="https://twitter.com/rskvp93">@rskvp93</a>) of Viettel Cyber Security

Revision History

  • 2020-12-08: Information published.