First published: Wed May 31 2023(Updated: )
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2023.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-34225.
The severity of CVE-2023-34225 is medium with a score of 5.4.
The affected software of CVE-2023-34225 is JetBrains TeamCity before version 2023.05.
CVE-2023-34225 allows for stored XSS (cross-site scripting) attacks in the NuGet feed page of JetBrains TeamCity before version 2023.05.
Yes, a fix is available for CVE-2023-34225. It is recommended to update to JetBrains TeamCity version 2023.05 or later.