First published: Fri Feb 25 2022(Updated: )
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2021.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-24340 is critical.
The affected software for CVE-2022-24340 is JetBrains TeamCity before version 2021.2.1.
XXE stands for XML External Entity and refers to a vulnerability that allows an attacker to read files or execute arbitrary code by exploiting the processing of XML inputs.
To fix CVE-2022-24340, it is recommended to update JetBrains TeamCity to version 2021.2.1 or later.
You can find more information about CVE-2022-24340 in the JetBrains Security Bulletin Q4 2021: https://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/