PT-2024-3960 · Jetbrains · Teamcity

Published

2024-05-29

·

Updated

2026-03-02

·

CVE-2024-36371

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2023.05.6 JetBrains TeamCity versions prior to 2023.11.5
Description The issue is related to a stored XSS in the Commit status publisher, which can be exploited by a remote attacker to conduct cross-site scripting attacks. This is due to the lack of protection measures for the web page structure.
Recommendations For versions prior to 2023.05.6, update to version 2023.05.6 or later. For versions prior to 2023.11.5, update to version 2023.11.5 or later. As a temporary workaround, consider disabling the Commit status publisher feature until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-04374
CVE-2024-36371

Affected Products

Teamcity