First published: Mon Mar 27 2023(Updated: )
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2022.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-48427.
The severity of CVE-2022-48427 is medium (CVSS score 5.4).
The affected software is JetBrains TeamCity before version 2022.10.3.
The vulnerability manifests as stored XSS on the 'Pending changes' and 'Changes' tabs in JetBrains TeamCity.
To fix CVE-2022-48427, update JetBrains TeamCity to version 2022.10.3 or later.