VYPR
High severity7.5NVD Advisory· Published Mar 12, 2020· Updated Jun 17, 2026

CVE-2020-0758

CVE-2020-0758

Description

An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.

Affected products

13
  • cpe:2.3:a:microsoft:team_foundation_server:2017:update3.1:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:microsoft:team_foundation_server:2017:update3.1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:team_foundation_server:2018:update1.2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:team_foundation_server:2018:update3.2:*:*:*:*:*:*
    • (no CPE)range: 2017 Update 3.1
    • (no CPE)range: Update 1.2
  • cpe:2.3:o:microsoft:azure_devops_server:2019.0.1:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:microsoft:azure_devops_server:2019.0.1:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:azure_devops_server:2019:update1.1:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:azure_devops_server:2019:update1:*:*:*:*:*:*
    • (no CPE)
  • Microsoft/Azure Devopscpe-rescue3 versions
    2019.0.1+ 2 more
    • (no CPE)range: 2019.0.1
    • (no CPE)range: Update 1
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.