First published: Tue Oct 01 2019(Updated: )
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | =2018.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15038 has a medium severity rating due to the lack of security-related HTTP headers in JetBrains TeamCity.
To fix CVE-2019-15038, upgrade to JetBrains TeamCity version 2019.1 or later.
CVE-2019-15038 specifically affects JetBrains TeamCity version 2018.2.4.
CVE-2019-15038 introduces potential security risks due to the absence of HTTP security headers, which may allow for various attacks.
CVE-2019-15038 was discovered prior to the release of JetBrains TeamCity 2019.1, which included the fix.