CVE-2024-36470: Critical severity jetbrains teamcity vulnerability
Published May 29, 2024
·Updated
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
Affected Software
5 affected components
JetBrains TeamCity<2022.04.7, <2022.10.6, <2023.05.6, <2023.11.5
JetBrains TeamCity<2022.04.7
JetBrains TeamCity>=2022.10<2022.10.6
JetBrains TeamCity>=2023.05<2023.05.6
JetBrains TeamCity>=2023.11<2023.11.5
Event History
May 29, 2024
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36470?
CVE-2024-36470 is classified as a high-severity vulnerability due to its ability to allow authentication bypass in certain edge cases.
2
How do I fix CVE-2024-36470?
To fix CVE-2024-36470, upgrade JetBrains TeamCity to the latest version available beyond 2022.04.7, 2022.10.6, 2023.05.6, or 2023.11.5.
3
What systems are affected by CVE-2024-36470?
CVE-2024-36470 affects JetBrains TeamCity versions prior to 2022.04.7, 2022.10.6, 2023.05.6, and 2023.11.5.
4
What are the potential impacts of CVE-2024-36470?
The potential impacts of CVE-2024-36470 include unauthorized access to sensitive data and resources within TeamCity.
5
Is CVE-2024-36470 exploitable remotely?
Yes, CVE-2024-36470 can be exploited remotely under specific conditions that allow an attacker to bypass authentication.