CVE-2024-24937: XSS
Published Feb 6, 2024
·Updated
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
Affected Software
1 affected component
JetBrains TeamCity<2023.11.2
Event History
Feb 6, 2024
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24937?
CVE-2024-24937 is classified as a medium severity vulnerability due to the potential for stored XSS attacks in JetBrains TeamCity.
2
How do I fix CVE-2024-24937?
To fix CVE-2024-24937, upgrade your JetBrains TeamCity installation to version 2023.11.2 or later.
3
What does CVE-2024-24937 affect?
CVE-2024-24937 affects all versions of JetBrains TeamCity prior to 2023.11.2.
4
Can CVE-2024-24937 be exploited remotely?
Yes, CVE-2024-24937 can be exploited remotely, allowing attackers to execute stored XSS attacks.
5
What are the implications of CVE-2024-24937 for users?
Users affected by CVE-2024-24937 may experience unauthorized access to their accounts or data due to the stored XSS vulnerability.