CVE-2021-43202: Critical severity jetbrains teamcity vulnerability
Published Nov 30, 2021
·Updated
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
Affected Software
1 affected component
JetBrains TeamCity<2021.1.3
Event History
Nov 30, 2021
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43202?
CVE-2021-43202 is classified as a medium severity vulnerability due to the absence of the X-Frame-Options header.
2
How do I fix CVE-2021-43202?
To fix CVE-2021-43202, update JetBrains TeamCity to version 2021.1.3 or later where the X-Frame-Options header is implemented.
3
What are the potential impacts of CVE-2021-43202?
The absence of the X-Frame-Options header in CVE-2021-43202 can lead to clickjacking attacks.
4
Which versions of JetBrains TeamCity are affected by CVE-2021-43202?
CVE-2021-43202 affects all versions of JetBrains TeamCity prior to 2021.1.3.
5
Is CVE-2021-43202 easy to exploit?
CVE-2021-43202 can be exploited by attackers with minimal technical knowledge using clickjacking techniques.