CVE-2024-36366: XSS
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36366?
CVE-2024-36366 is classified as a high severity vulnerability due to the potential for XSS exploitation.
How do I fix CVE-2024-36366?
To fix CVE-2024-36366, upgrade JetBrains TeamCity to version 2022.04.8 or later, 2022.10.7 or later, 2023.05.7 or later, or 2023.11.6 or later.
What is the impact of CVE-2024-36366?
The impact of CVE-2024-36366 allows attackers to execute arbitrary JavaScript in the context of the user's session.
Which versions of JetBrains TeamCity are affected by CVE-2024-36366?
CVE-2024-36366 affects JetBrains TeamCity versions before 2022.04.7, 2022.10.6, 2023.05.6, and 2023.11.5.
How can XSS vulnerabilities like CVE-2024-36366 be exploited?
XSS vulnerabilities like CVE-2024-36366 can be exploited through malicious scripts embedded in reports or filtered output that users may interact with.