First published: Wed May 31 2023(Updated: )
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2023.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the TeamCity reflected XSS vulnerability is CVE-2023-34226.
The severity of CVE-2023-34226 is medium with a CVSS score of 6.1.
The affected software for CVE-2023-34226 is JetBrains TeamCity before version 2023.05.
The XSS vulnerability in JetBrains TeamCity can be exploited by an attacker injecting malicious code into the Subscriptions page and tricking a user into executing it.
Yes, a fix for CVE-2023-34226 is available in JetBrains TeamCity version 2023.05 and later.