PT-2024-9848 · Jetbrains · Teamcity

Published

2024-12-20

·

Updated

2025-01-02

·

CVE-2024-56354

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions: JetBrains TeamCity versions prior to 2024.12
Description: The issue is related to insufficient protection of registration data in JetBrains TeamCity, a continuous integration and continuous delivery (CI/CD) system. This allows a remote attacker to disclose protected information. Users with view settings permission could access the password field value.
Recommendations: For versions prior to 2024.12, update to version 2024.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the view settings permission to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-11626
CVE-2024-56354

Affected Products

Teamcity