First published: Wed Jul 12 2023(Updated: )
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
Credit: security@jetbrains.com security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2023.05.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this JetBrains TeamCity vulnerability is CVE-2023-38066.
The severity level of CVE-2023-38066 is medium.
The vulnerability in JetBrains TeamCity before 2023.05.1 occurs through reflected XSS via the Referer header during artifact downloads.
The versions up to but excluding 2023.05.1 of JetBrains TeamCity are affected by CVE-2023-38066.
To fix the vulnerability in JetBrains TeamCity, it is recommended to update to version 2023.05.1 or newer.