{"id":60432,"date":"2020-12-08T13:17:59","date_gmt":"2020-12-08T21:17:59","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/devops\/?p=60432"},"modified":"2020-12-17T16:16:12","modified_gmt":"2020-12-18T00:16:12","slug":"december-patches-for-azure-devops-server-and-team-foundation-server","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/devops\/december-patches-for-azure-devops-server-and-team-foundation-server\/","title":{"rendered":"December patches for Azure DevOps Server and Team Foundation Server"},"content":{"rendered":"<p>This month, we are releasing fixes for security vulnerabilities that impact our self-hosted product, <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/devops\/server\/\">Azure DevOps Server<\/a>, as well as the following older Team Foundation Server releases: TFS 2015, TFS 2017 and TFS 2018.<\/p>\n<p>The following vulnerabilities will be fixed with this patch:<\/p>\n<ul>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020-17135\">CVE-2020-17135<\/a>: Azure DevOps Server Spoofing Vulnerability<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020-17145\">CVE-2020-17145<\/a>: Azure DevOps Server and Team Foundation Services Spoofing Vulnerability<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020-1325\">CVE-2020-1325<\/a>: Azure DevOps Server Spoofing Vulnerability<\/li>\n<li>Fix issue with TFVC not processing all results<\/li>\n<\/ul>\n<h3>Azure DevOps Server 2020 Patch 1<\/h3>\n<p>If you have Azure DevOps Server 2020, you should install <a href=\"https:\/\/aka.ms\/azdev2020patch\">Azure DevOps Server 2020 Patch 1<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>devops2020patch1.exe CheckInstall<\/code>, devops2020patch1.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[INSTALL_DIR]\\Azure DevOps Server 2020\\Application Tier\\bin\\Microsoft.Teamfoundation.Framework.Server.dll<\/code>. Azure DevOps Server 2020 is installed to <code>c:\\Program Files\\Azure DevOps Server 2020<\/code> by default. After installing Azure DevOps Server 2020 Patch 1, the version will be <strong>18&#46;170.30723.6<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h3>Azure DevOps Server 2019.1.1 Patch 6<\/h3>\n<p>If you have Azure DevOps Server 2019 Update 1.1, you should install <a href=\"https:\/\/aka.ms\/azdev2019.1patch\">Azure DevOps Server 2019 Update 1.1 Patch 6<\/a>. Please see the <a href=\"https:\/\/docs.microsoft.com\/azure\/devops\/server\/release-notes\/azuredevops2019u1?view=azure-devops&amp;branch=releasenotes%2Fdecsecpatches#azure-devops-server-2019-update-11-patch-6-release-date-december-8-2020\">release notes<\/a> for AzurePowerShellV4 task installation instructions.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>devops2019.1.1patch6.exe CheckInstall<\/code>, devops2019.1.1patch6.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[INSTALL_DIR]\\Azure DevOps Server 2019\\Application Tier\\Web Services\\bin\\Microsoft.VisualStudio.Services.Feed.Server.dll<\/code>. Azure DevOps Server 2019 is installed to <code>c:\\Program Files\\Azure DevOps Server 2019<\/code> by default. After installing Azure DevOps Server 2019.1.1 Patch 6, the version will be <strong>17&#46;153.30723.5<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h3>Azure DevOps Server 2019.0.1 Patch 9<\/h3>\n<p>If you have Azure DevOps Server 2019, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=2089023\">Azure DevOps Server 2019.0.1<\/a>. Once on 2019.0.1, install <a href=\"https:\/\/aka.ms\/azdev2019.0.1patch\">Azure DevOps Server 2019.0.1 Patch 9<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>devops2019.0.1patch9.exe CheckInstall<\/code>, devops2019.0.1patch9.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Framework.Server.dll<\/code>. Azure DevOps Server 2019 is installed to <code>c:\\Program Files\\Azure DevOps Server 2019<\/code> by default. After installing Azure DevOps Server 2019.0.1 Patch 9, the version will be <strong>17&#46;143.30723.4<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS 2018 Update 3.2 Patch 14<\/h3>\n<p>If you have TFS 2018 Update 2 or Update 3, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=2008534\">TFS 2018 Update 3.2<\/a>. Once on Update 3.2, install <a href=\"https:\/\/aka.ms\/tfs2018.3.2patch\">TFS 2018 Update 3.2 Patch 14<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2018.3.2patch14.exe CheckInstall<\/code>, tfs2018.3.2patch14.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.WorkItemTracking.Web.dll<\/code>. TFS 2018 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 2018<\/code> by default. After installing TFS 2018 Update 3.2 Patch 14, the version will be <strong>16&#46;131.30724.3<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS 2018 Update 1.2 Patch 9<\/h3>\n<p>If you have TFS 2018 RTW or Update 1, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=866620\">TFS 2018 Update 1.2<\/a>. Once on Update 1.2, install <a href=\"https:\/\/aka.ms\/tfs2018.1.2patch\">TFS 2018 Update 1.2 Patch 9<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2018.1.2patch9.exe CheckInstall<\/code>, tfs2018.1.2patch9.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Server.WebAccess.Admin.dll<\/code>. TFS 2018 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 2018<\/code> by default. After installing TFS 2018 Update 1.2 Patch 9, the version will be <strong>16&#46;122.30723.1<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS 2017 Update 3.1 Patch 12<\/h3>\n<p>If you have TFS 2017, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?LinkId=857134\">TFS 2017 Update 3.1<\/a>. Once on Update 3.1, install <a href=\"https:\/\/aka.ms\/tfs2017.3.1patch\">TFS 2017 Update 3.1 Patch 12<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2017.3.1patch12.exe CheckInstall<\/code>, tfs2017.3.1patch12.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Server.WebAccess.Admin.dll<\/code>. TFS 2017 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 15.0<\/code> by default. After installing TFS 2017 Update 3.1 Patch 12, the version will be <strong>15&#46;117.30801.0<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h3>TFS Update 2015.4.2 Patch 7<\/h3>\n<p>If you have TFS 2015, you should first update to <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=844068\">TFS 2015 Update 4.2<\/a>. Once on Update 4.2, install <a href=\"https:\/\/aka.ms\/tfs2015.4.2patch\">TFS 2015 Update 4.2 Patch 7<\/a>.<\/p>\n<p><strong>Verifying Installation<\/strong><\/p>\n<ul>\n<li>\n<p><strong>Option 1<\/strong>: Run <code>tfs2015.4.2patch7.exe CheckInstall<\/code>, tfs2015.4.2patch17.exe is the file that is downloaded from the link above. The output of the command will either say that the patch has been installed, or that is not installed.<\/p>\n<\/li>\n<li>\n<p><strong>Option 2<\/strong>: Check the version of the following file: <code>[TFS_INSTALL_DIR]\\Application Tier\\Web Services\\bin\\Microsoft.TeamFoundation.Framework.Server.dll<\/code>. TFS 2015 is installed to <code>c:\\Program Files\\Microsoft Team Foundation Server 14.0<\/code> by default. After installing TFS 2015 Update 4.2 Patch 7, the version will be <strong>14&#46;114.30730.0<\/strong>.<\/p>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>This month, we are releasing fixes for security vulnerabilities that impact our self-hosted product, Azure DevOps Server, as well as the following older Team Foundation Server releases: TFS 2015, TFS 2017 and TFS 2018.<\/p>\n","protected":false},"author":1006,"featured_media":56758,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[253],"tags":[],"class_list":["post-60432","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure-devops-server"],"acf":[],"blog_post_summary":"<p>This month, we are releasing fixes for security vulnerabilities that impact our self-hosted product, Azure DevOps Server, as well as the following older Team Foundation Server releases: TFS 2015, TFS 2017 and TFS 2018.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/60432","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/users\/1006"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/comments?post=60432"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/60432\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media\/56758"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media?parent=60432"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/categories?post=60432"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/tags?post=60432"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}