CVE-2019-12157: Input Validation
Published Oct 2, 2019
·Updated
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
Affected Software
6 affected components
JetBrains TeamCity<2018.2.5
JetBrains UpSource<=2018.2
JetBrains UpSource=2018.2-build_1013
JetBrains UpSource=2018.2-build_1141
JetBrains UpSource=2018.2-build_1154
JetBrains UpSource=2018.2-build_1291
Event History
Oct 2, 2019
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12157?
CVE-2019-12157 is a vulnerability in JetBrains UpSource versions before 2018.2 build 1293 that allows credential disclosure via RPC commands.
2
What software is affected by CVE-2019-12157?
JetBrains TeamCity and JetBrains UpSource versions before 2018.2 build 1293 are affected by CVE-2019-12157.
3
How severe is CVE-2019-12157?
CVE-2019-12157 has a severity level of 9.8 (Critical).
4
How can I fix CVE-2019-12157?
To fix CVE-2019-12157, you should update your JetBrains UpSource software to version 2018.2 build 1293 or later.
5
Where can I find more information about CVE-2019-12157?
You can find more information about CVE-2019-12157 in the JetBrains security bulletin for Q2 2019.