First published: Wed Apr 22 2020(Updated: )
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2019.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11688 has a medium severity rating due to session persistence issues.
To fix CVE-2020-11688, upgrade TeamCity to version 2019.2.1 or later.
CVE-2020-11688 affects JetBrains TeamCity versions prior to 2019.2.1.
CVE-2020-11688 allows for potential unauthorized access since the application state remains active after user sessions end.
You are at risk for CVE-2020-11688 if you are using a version of JetBrains TeamCity earlier than 2019.2.1.