CVE-2019-15848: XSS
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15848?
CVE-2019-15848 is rated as a high severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2019-15848?
To fix CVE-2019-15848, upgrade JetBrains TeamCity to version 2019.1.2 or later, which addresses this security issue.
What types of attacks can CVE-2019-15848 enable?
CVE-2019-15848 can enable cross-site scripting attacks, allowing arbitrary HTTP requests to be sent under the logged-in user's identity.
Which versions of JetBrains TeamCity are affected by CVE-2019-15848?
CVE-2019-15848 affects JetBrains TeamCity versions 2019.1 and 2019.1.1.
Is user interaction required to exploit CVE-2019-15848?
Yes, user interaction is typically required for an attacker to exploit CVE-2019-15848 through linked or injected malicious scripts.