First published: Tue Jan 21 2025(Updated: )
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2024.12.1 | |
JetBrains TeamCity | <2024.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24460 is classified as a high severity vulnerability due to improper access control in JetBrains TeamCity.
To fix CVE-2025-24460, upgrade JetBrains TeamCity to version 2024.12.1 or later.
CVE-2025-24460 affects JetBrains TeamCity versions prior to 2024.12.1.
CVE-2025-24460 allows unauthorized users to see project names in the agent pool.
Yes, CVE-2025-24460 can be exploited easily due to its improper access control mechanism.