CVE-2025-47853: XSS
Published May 20, 2025
·Updated
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
Affected Software
2 affected components
JetBrains TeamCity<2025.03.2
JetBrains TeamCity<2025.03.2
Event History
May 20, 2025
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47853?
The severity of CVE-2025-47853 is categorized as high due to the potential for stored XSS attacks.
2
How do I fix CVE-2025-47853?
To fix CVE-2025-47853, upgrade JetBrains TeamCity to version 2025.03.2 or later.
3
What types of attacks are possible with CVE-2025-47853?
CVE-2025-47853 allows for stored cross-site scripting (XSS) attacks through Jira integration.
4
Who is affected by CVE-2025-47853?
Users of JetBrains TeamCity versions prior to 2025.03.2 are affected by CVE-2025-47853.
5
What are the implications of CVE-2025-47853 for users?
The implications include the risk of malicious scripts being executed in the context of a user’s browser, potentially leading to data theft or session hijacking.