CVE-2024-35300: XSS
Published May 16, 2024
·Updated
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
Affected Software
1 affected component
JetBrains TeamCity=2024.03
Event History
May 16, 2024
CVE Published
via MITRE·10:31 AM
Data Sourced
via MITRE·10:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35300?
CVE-2024-35300 is classified as a medium severity vulnerability due to potential stored XSS attacks.
2
How do I fix CVE-2024-35300?
To fix CVE-2024-35300, upgrade JetBrains TeamCity to version 2024.03.1 or later.
3
What types of attacks does CVE-2024-35300 allow?
CVE-2024-35300 allows for stored cross-site scripting (XSS) attacks in the available updates page.
4
Is my version vulnerable to CVE-2024-35300?
If you are using JetBrains TeamCity version 2024.03, then you are vulnerable to CVE-2024-35300.
5
Are there any workarounds for CVE-2024-35300?
There are no documented workarounds for CVE-2024-35300, so upgrading is necessary for mitigation.