PT-2024-9849 · Jetbrains · Teamcity
Published
2024-12-20
·
Updated
2025-01-02
·
CVE-2024-56352
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
JetBrains TeamCity versions prior to 2024.12
Description:
The issue allows for stored Cross Site Scripting (XSS) via the image name on the agent details page. This can be exploited by a remote attacker to conduct an inter-site scripting attack.
Recommendations:
For versions prior to 2024.12, update to version 2024.12 or later to resolve the issue.
As a temporary workaround, consider restricting access to the agent details page until a patch is available.
Avoid using the image name field in the agent details page until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamcity