PT-2024-9849 · Jetbrains · Teamcity

Published

2024-12-20

·

Updated

2025-01-02

·

CVE-2024-56352

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: JetBrains TeamCity versions prior to 2024.12
Description: The issue allows for stored Cross Site Scripting (XSS) via the image name on the agent details page. This can be exploited by a remote attacker to conduct an inter-site scripting attack.
Recommendations: For versions prior to 2024.12, update to version 2024.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the agent details page until a patch is available. Avoid using the image name field in the agent details page until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-11627
CVE-2024-56352

Affected Products

Teamcity