{"id":58650,"date":"2020-03-10T09:37:09","date_gmt":"2020-03-10T17:37:09","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/devops\/?p=58650"},"modified":"2020-05-14T06:38:31","modified_gmt":"2020-05-14T14:38:31","slug":"march-patches-for-azure-devops-server-and-team-foundation-server","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/devops\/march-patches-for-azure-devops-server-and-team-foundation-server\/","title":{"rendered":"March patches for Azure DevOps Server and Team Foundation Server"},"content":{"rendered":"<p>This month, we are releasing fixes for security vulnerabilities that impact our self-hosted product, <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/devops\/server\/\">Azure DevOps Server 2019<\/a>, as well as the following older Team Foundation Server releases: TFS 2015, TFS 2017 and TFS 2018.<\/p>\n<p>The following vulnerabilities will be fixed with this patch:<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0700\">CVE-2020-0700<\/a> | Cross-site Scripting Vulnerability<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0758\">CVE-2020-0758<\/a> | Elevation of Privilege Vulnerability<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0815\">CVE 2020-0815<\/a> | Elevation of Privilege Vulnerability<\/p>\n<\/li>\n<\/ul>\n<h3>Azure DevOps Server 2019.1.1 Patch 1<\/h3>\n<p>If you have Azure DevOps Server 2019 Update 1.1, you should install <a href=\"https:\/\/aka.ms\/azdev2019.1patch\">Azure DevOps Server 2019 Update 1.1 Patch 1<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>devops2019.1.1patch1.exe CheckInstall<\/code>, devops2019.1.1patch1.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[INSTALL_DIR]\\Azure DevOps Server 2019\\Application Tier\\Web Services\\bin\\Microsoft.VisualStudio.Services.Feed.Server.dll<\/code>. Azure DevOps Server 2019 is installed to <code>c:\\Program Files\\Azure DevOps Server 2019<\/code> by default. After installing Azure DevOps Server 2019.1.1 Patch 1, the version will be 17.153.29904.2.<\/p>\n<\/li>\n<\/ul>\n<h3>Azure DevOps Server 2019.0.1 Patch 5<\/h3>\n<p>If you have Azure DevOps Server 2019, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=2089023\">Azure DevOps Server 2019.0.1<\/a>. Once on 2019.0.1, install <a href=\"https:\/\/aka.ms\/azdev2019.0.1patch\">Azure DevOps Server 2019.0.1 Patch 5<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>devops2019.0.1patch5.exe CheckInstall<\/code>, devops2019.0.1patch5.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Framework.Server.dll<\/code>. Azure DevOps Server 2019 is installed to <code>c:\\Program Files\\Azure DevOps Server 2019<\/code> by default. After installing Azure DevOps Server 2019.0.1 Patch 5, the version will be 17.143.29825.2.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS 2018 Update 3.2 Patch 9<\/h3>\n<p>If you have TFS 2018 Update 2 or Update 3, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=2008534\">TFS 2018 Update 3.2<\/a>. Once on Update 3.2, install <a href=\"https:\/\/aka.ms\/tfs2018.3.2patch\">TFS 2018 Update 3.2 Patch 9<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2018.3.2patch9.exe CheckInstall<\/code>, tfs2018.3.2patch9.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.WorkItemTracking.Web.dll<\/code>. TFS 2018 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 2018<\/code> by default. After installing TFS 2018 Update 3.2 Patch 9, the version will be 16.131.29825.3.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS 2018 Update 1.2 Patch 8<\/h3>\n<p>If you have TFS 2018 RTW or Update 1, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=866620\">TFS 2018 Update 1.2<\/a>. Once on Update 1.2, install <a href=\"https:\/\/aka.ms\/tfs2018.1.2patch\">TFS 2018 Update 1.2 Patch 8<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2018.1.2patch8.exe CheckInstall<\/code>, tfs2018.1.2patch8.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Server.WebAccess.Admin.dll<\/code>. TFS 2018 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 2018<\/code> by default. After installing TFS 2018 Update 1.2 Patch 8, the version will be 16.122.29825.4.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS 2017 Update 3.1 Patch 10<\/h3>\n<p>If you have TFS 2017, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=857134\">TFS 2017 Update 3.1<\/a>. Once on Update 3.1, install <a href=\"https:\/\/aka.ms\/tfs2017.3.1patch\">TFS 2017 Update 3.1 Patch 10<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2017.3.1patch10.exe CheckInstall<\/code>, tfs2017.3.1patch10.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Server.WebAccess.Admin.dll<\/code>. TFS 2017 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 15.0<\/code> by default. After installing TFS 2017 Update 3.1 Patch 10, the version will be 15.117.29825.0.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS Update 2015.4.2 Patch 5<\/h3>\n<p>If you have TFS 2015, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=844068\">TFS 2015 Update 4.2<\/a>. Once on Update 4.2, install <a href=\"https:\/\/aka.ms\/tfs2015.4.2patch\">TFS 2015 Update 4.2 Patch 5<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2015.4.2patch11.exe CheckInstall<\/code>, tfs2015.4.2patch11.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Framework.Server.dll<\/code>. TFS 2015 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 14.0<\/code> by default. After installing TFS 2015 Update 4.2 Patch 5, the version will be 14.114.29825.0.<\/p>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>This month, we are releasing fixes for security vulnerabilities that impact our self-hosted product, Azure DevOps Server 2019, as well as the following older Team Foundation Server releases: TFS 2015, TFS 2017 and TFS 2018.<\/p>\n","protected":false},"author":1006,"featured_media":56758,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[224],"tags":[],"class_list":["post-58650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure"],"acf":[],"blog_post_summary":"<p>This month, we are releasing fixes for security vulnerabilities that impact our self-hosted product, Azure DevOps Server 2019, as well as the following older Team Foundation Server releases: TFS 2015, TFS 2017 and TFS 2018.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/58650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/users\/1006"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/comments?post=58650"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/58650\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media\/56758"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media?parent=58650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/categories?post=58650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/tags?post=58650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}