#VU17013 Information disclosure in Team Foundation Server - CVE-2019-0647
Published: January 16, 2019
Team Foundation Server
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to Team Foundation Server does not properly handle variables marked as secret. A remote authenticated attacker can create a task group with a task containing a secret variable and gain access to variables that belong to other users.