CVE-2015-1313: Input Validation
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this JetBrains TeamCity vulnerability?
The vulnerability ID for this JetBrains TeamCity vulnerability is CVE-2015-1313.
What is the severity rating of CVE-2015-1313?
The severity rating of CVE-2015-1313 is medium, with a score of 6.5.
What is the affected software for CVE-2015-1313?
JetBrains TeamCity versions 8 and 9 before 9.0.2 are affected by CVE-2015-1313.
How does CVE-2015-1313 allow bypass of account-creation restrictions?
CVE-2015-1313 allows bypass of account-creation restrictions by deducing the required request data from HTML and JavaScript files returned to the web browser after an initial unauthenticated request.
How can I fix CVE-2015-1313?
To fix CVE-2015-1313, it is recommended to update JetBrains TeamCity to version 9.0.2 or later.