CVE-2019-15038: High severity jetbrains teamcity vulnerability
Published Oct 1, 2019
·Updated
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
Affected Software
1 affected component
JetBrains TeamCity=2018.2.4
Event History
Oct 1, 2019
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15038?
CVE-2019-15038 has a medium severity rating due to the lack of security-related HTTP headers in JetBrains TeamCity.
2
How do I fix CVE-2019-15038?
To fix CVE-2019-15038, upgrade to JetBrains TeamCity version 2019.1 or later.
3
Which versions of JetBrains TeamCity are affected by CVE-2019-15038?
CVE-2019-15038 specifically affects JetBrains TeamCity version 2018.2.4.
4
What vulnerabilities does CVE-2019-15038 introduce?
CVE-2019-15038 introduces potential security risks due to the absence of HTTP security headers, which may allow for various attacks.
5
When was CVE-2019-15038 discovered?
CVE-2019-15038 was discovered prior to the release of JetBrains TeamCity 2019.1, which included the fix.