CVE-2024-36363: XSS
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36363?
CVE-2024-36363 is classified as a high severity vulnerability due to the potential for Stored XSS attacks.
How do I fix CVE-2024-36363?
To fix CVE-2024-36363, upgrade JetBrains TeamCity to version 2022.04.7, 2022.10.6, 2023.05.6, or 2023.11.5 or later.
What types of vulnerabilities does CVE-2024-36363 include?
CVE-2024-36363 includes several Stored XSS vulnerabilities that can be exploited in code inspection reports.
Which versions of JetBrains TeamCity are affected by CVE-2024-36363?
CVE-2024-36363 affects JetBrains TeamCity versions prior to 2022.04.7, between 2022.10 and 2022.10.6, between 2023.05 and 2023.05.6, and between 2023.11 and 2023.11.5.
What are Stored XSS vulnerabilities in the context of CVE-2024-36363?
Stored XSS vulnerabilities in CVE-2024-36363 allow attackers to inject malicious scripts that are stored on the server and executed in the browser of users accessing the affected application.