CVE-2024-36365: High severity jetbrains teamcity vulnerability
Published May 29, 2024
·Updated
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
Affected Software
5 affected components
JetBrains TeamCity<2022.04.7
JetBrains TeamCity>=2022.10<2022.10.6
JetBrains TeamCity>=2023.05<2023.05.6
JetBrains TeamCity>=2023.11<2023.11.5
JetBrains TeamCity>=2024.03<2024.03.2
Event History
May 29, 2024
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36365?
CVE-2024-36365 has a moderate severity level due to the potential for third-party agents to impersonate cloud agents.
2
How do I fix CVE-2024-36365?
To fix CVE-2024-36365, upgrade JetBrains TeamCity to a version later than 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, or 2024.03.2.
3
What versions of JetBrains TeamCity are affected by CVE-2024-36365?
CVE-2024-36365 affects JetBrains TeamCity versions prior to 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, and 2024.03.2.
4
What are the potential impacts of CVE-2024-36365?
The potential impacts of CVE-2024-36365 include unauthorized access and the ability for attackers to impersonate legitimate cloud agents.
5
Is there a workaround for CVE-2024-36365 before applying patches?
There is no official workaround for CVE-2024-36365, so it is recommended to patch with available updates.