CVE-2024-36368: XSS
Published May 29, 2024
·Updated
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
Affected Software
4 affected components
JetBrains TeamCity<2022.04.7
JetBrains TeamCity>=2022.10<2022.10.6
JetBrains TeamCity>=2023.05<2023.05.6
JetBrains TeamCity>=2023.11<2023.11.5
Event History
May 29, 2024
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36368?
CVE-2024-36368 is classified as a reflected XSS vulnerability that can lead to potential exploitation by attackers.
2
How do I fix CVE-2024-36368?
To mitigate CVE-2024-36368, upgrade JetBrains TeamCity to versions 2022.04.7, 2022.10.6, 2023.05.6, or 2023.11.5 or later.
3
What versions of JetBrains TeamCity are affected by CVE-2024-36368?
CVE-2024-36368 affects JetBrains TeamCity versions prior to 2022.04.7 and 2022.10.6, 2023.05.6, and 2023.11.5.
4
What is reflected XSS in the context of CVE-2024-36368?
Reflected XSS in CVE-2024-36368 refers to the capability to execute malicious scripts through manipulated OAuth provider configuration.
5
Is there a workaround for CVE-2024-36368 if I cannot upgrade immediately?
Currently, patching to the latest versions is the recommended approach, as specific workarounds for CVE-2024-36368 are not documented.