PT-2019-13945 · Jetbrains · Teamcity

Published

2019-09-26

·

Updated

2019-10-03

·

CVE-2019-15036

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2018.2.5 JetBrains TeamCity versions prior to 2019.1
Description An issue was discovered that allows a TeamCity Project administrator to execute any command on the server machine.
Recommendations For versions prior to 2018.2.5, update to TeamCity 2018.2.5 or later. For versions prior to 2019.1, update to TeamCity 2019.1 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15036

Affected Products

Teamcity