First published: Thu Sep 05 2019(Updated: )
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | =2019.1 | |
JetBrains TeamCity | =2019.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15848 is rated as a high severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2019-15848, upgrade JetBrains TeamCity to version 2019.1.2 or later, which addresses this security issue.
CVE-2019-15848 can enable cross-site scripting attacks, allowing arbitrary HTTP requests to be sent under the logged-in user's identity.
CVE-2019-15848 affects JetBrains TeamCity versions 2019.1 and 2019.1.1.
Yes, user interaction is typically required for an attacker to exploit CVE-2019-15848 through linked or injected malicious scripts.