CVE-2019-1306
critical · 9.8A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
9.8
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2019-09-11
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | team_foundation_server | 2018 |
| microsoft | azure_devops_server | 2019 |
| microsoft | azure_devops_server | 2019.0.1 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-1306