PT-2024-20674 · Jetbrains · Teamcity

Published

2024-02-05

·

Updated

2024-02-09

·

CVE-2024-24936

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2023.11.2
Description The issue is related to missing access control at the S3 Artifact Storage plugin endpoint. This could potentially allow unauthorized access.
Recommendations For versions prior to 2023.11.2, update to version 2023.11.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the S3 Artifact Storage plugin endpoint until a patch is applied.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-24936

Affected Products

Teamcity