CVE-2024-36369: XSS
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36369?
CVE-2024-36369 has a severity rating that indicates a significant risk of stored cross-site scripting (XSS) attacks in affected JetBrains TeamCity versions.
How do I fix CVE-2024-36369?
To fix CVE-2024-36369, upgrade JetBrains TeamCity to version 2022.04.7, 2022.10.6, 2023.05.6, or 2023.11.5 or later.
Which versions of JetBrains TeamCity are affected by CVE-2024-36369?
Versions of JetBrains TeamCity prior to 2022.04.7, between 2022.10.0 and 2022.10.6, and versions between 2023.05.0 and 2023.05.6, as well as between 2023.11.0 and 2023.11.5 are affected.
What type of vulnerability is CVE-2024-36369?
CVE-2024-36369 is a stored cross-site scripting (XSS) vulnerability affecting JetBrains TeamCity.
Is there a patch available for CVE-2024-36369?
Yes, the issue is mitigated by installing the patched versions of JetBrains TeamCity.