First published: Wed May 29 2024(Updated: )
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2022.04.7 | |
JetBrains TeamCity | >=2022.10<2022.10.6 | |
JetBrains TeamCity | >=2023.05<2023.05.6 | |
JetBrains TeamCity | >=2023.11<2023.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36363 is classified as a high severity vulnerability due to the potential for Stored XSS attacks.
To fix CVE-2024-36363, upgrade JetBrains TeamCity to version 2022.04.7, 2022.10.6, 2023.05.6, or 2023.11.5 or later.
CVE-2024-36363 includes several Stored XSS vulnerabilities that can be exploited in code inspection reports.
CVE-2024-36363 affects JetBrains TeamCity versions prior to 2022.04.7, between 2022.10 and 2022.10.6, between 2023.05 and 2023.05.6, and between 2023.11 and 2023.11.5.
Stored XSS vulnerabilities in CVE-2024-36363 allow attackers to inject malicious scripts that are stored on the server and executed in the browser of users accessing the affected application.