PT-2024-2340 · Jetbrains · Teamcity

Published

2024-03-21

·

Updated

2024-12-16

·

CVE-2024-29880

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2023.11
Description The issue is related to the use of dangerous methods or functions in the continuous integration and delivery (CI/CD) system, which may allow an attacker to escalate their privileges. Users with access to the agent machine might obtain permissions of the user running the agent process.
Recommendations For versions prior to 2023.11, update to version 2023.11 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-02288
CVE-2024-29880

Affected Products

Teamcity