PT-2024-7655 · Jetbrains+1 · Jetbrains Teamcity+2

Published

2024-08-16

·

Updated

2024-10-08

·

CVE-2024-43808

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2024.07.1
Description The issue exists due to inadequate protection of the web page structure in the HashiCorp Vault plugin of the JetBrains TeamCity CI/CD system. Exploitation of this issue may allow a remote attacker to conduct cross-site scripting.
Recommendations For versions prior to 2024.07.1, update to version 2024.07.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the HashiCorp Vault plugin to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-09098
CVE-2024-43808

Affected Products

Hashicorp Vault
Jetbrains Teamcity
Teamcity