First published: Tue Nov 30 2021(Updated: )
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2021.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43202 is classified as a medium severity vulnerability due to the absence of the X-Frame-Options header.
To fix CVE-2021-43202, update JetBrains TeamCity to version 2021.1.3 or later where the X-Frame-Options header is implemented.
The absence of the X-Frame-Options header in CVE-2021-43202 can lead to clickjacking attacks.
CVE-2021-43202 affects all versions of JetBrains TeamCity prior to 2021.1.3.
CVE-2021-43202 can be exploited by attackers with minimal technical knowledge using clickjacking techniques.