First published: Wed May 29 2024(Updated: )
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2024.03.2 | |
JetBrains TeamCity | <2024.03.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36374 is classified as a stored XSS vulnerability which can have a high impact on security.
To fix CVE-2024-36374, update JetBrains TeamCity to version 2024.03.2 or later.
The risks associated with CVE-2024-36374 include the potential for attackers to execute malicious scripts within the context of the application.
CVE-2024-36374 affects JetBrains TeamCity versions prior to 2024.03.2.
Yes, CVE-2024-36374 can be exploited remotely if the attacker has access to the build step settings.