CVE-2024-36367: XSS
Published May 29, 2024
·Updated
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
Affected Software
4 affected components
JetBrains TeamCity<2022.04.7
JetBrains TeamCity>=2022.10<2022.10.6
JetBrains TeamCity>=2023.05<2023.05.6
JetBrains TeamCity>=2023.11<2023.11.5
Event History
May 29, 2024
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36367?
CVE-2024-36367 is considered a medium severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2024-36367?
To fix CVE-2024-36367, upgrade JetBrains TeamCity to version 2022.04.7 or later, or to one of the later specified versions.
3
What type of vulnerability is CVE-2024-36367?
CVE-2024-36367 is a stored cross-site scripting (XSS) vulnerability.
4
Which versions of JetBrains TeamCity are affected by CVE-2024-36367?
CVE-2024-36367 affects JetBrains TeamCity versions before 2022.04.7, 2022.10.6, 2023.05.6, and 2023.11.5.
5
What is the impact of CVE-2024-36367?
The impact of CVE-2024-36367 allows an attacker to execute arbitrary scripts in the context of a user's session.