First published: Fri Aug 25 2023(Updated: )
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
Credit: security@jetbrains.com security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2023.05.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue in JetBrains TeamCity is CVE-2023-41249.
The severity of CVE-2023-41249 is medium (6.1).
CVE-2023-41249 is a reflected XSS vulnerability in JetBrains TeamCity before 2023.05.3 that allows malicious code to be injected and executed during the copying of Build Step.
JetBrains TeamCity versions up to exclusive 2023.05.3 are affected by CVE-2023-41249.
To fix CVE-2023-41249, it is recommended to update to JetBrains TeamCity version 2023.05.3 or later.