CVE-2022-24331: Critical severity jetbrains teamcity vulnerability
Published Feb 25, 2022
·Updated
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
Affected Software
1 affected component
JetBrains TeamCity<2021.4
Event History
Feb 25, 2022
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24331?
CVE-2022-24331 has been classified with a severity that indicates a risk due to the possibility of GitLab authentication impersonation.
2
How do I fix CVE-2022-24331?
To remediate CVE-2022-24331, upgrade JetBrains TeamCity to version 2021.1.4 or later.
3
What versions of JetBrains TeamCity are affected by CVE-2022-24331?
CVE-2022-24331 affects all versions of JetBrains TeamCity prior to 2021.1.4.
4
What type of vulnerability is CVE-2022-24331?
CVE-2022-24331 is an authentication vulnerability related to GitLab impersonation in JetBrains TeamCity.
5
Is there a workaround for CVE-2022-24331?
There are no official workarounds for CVE-2022-24331 other than applying the available update.