CVE-2025-24459: XSS
Published Jan 21, 2025
·Updated
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
Affected Software
2 affected components
JetBrains TeamCity<2024.12.1
JetBrains TeamCity<2024.12.1
Event History
Jan 21, 2025
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Nov 29, 57087
Event
via FIRST·02:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-24459?
CVE-2025-24459 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-24459?
To mitigate CVE-2025-24459, upgrade to JetBrains TeamCity version 2024.12.1 or later.
3
What impact does CVE-2025-24459 have on users?
CVE-2025-24459 allows attackers to execute arbitrary JavaScript in the context of the user’s session.
4
Which versions of JetBrains TeamCity are affected by CVE-2025-24459?
CVE-2025-24459 affects all JetBrains TeamCity versions prior to 2024.12.1.
5
Where can I find more details about CVE-2025-24459?
Detailed information regarding CVE-2025-24459 can be found in the JetBrains security issues fixed documentation.