First published: Wed May 29 2024(Updated: )
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2022.04.7 | |
JetBrains TeamCity | >=2022.10<2022.10.6 | |
JetBrains TeamCity | >=2023.05<2023.05.6 | |
JetBrains TeamCity | >=2023.11<2023.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36369 has a severity rating that indicates a significant risk of stored cross-site scripting (XSS) attacks in affected JetBrains TeamCity versions.
To fix CVE-2024-36369, upgrade JetBrains TeamCity to version 2022.04.7, 2022.10.6, 2023.05.6, or 2023.11.5 or later.
Versions of JetBrains TeamCity prior to 2022.04.7, between 2022.10.0 and 2022.10.6, and versions between 2023.05.0 and 2023.05.6, as well as between 2023.11.0 and 2023.11.5 are affected.
CVE-2024-36369 is a stored cross-site scripting (XSS) vulnerability affecting JetBrains TeamCity.
Yes, the issue is mitigated by installing the patched versions of JetBrains TeamCity.