PT-2024-9852 · Jetbrains · Jetbrains Teamcity+1
Published
2024-12-20
·
Updated
2025-01-02
·
CVE-2024-56351
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
JetBrains TeamCity versions prior to 2024.12
Description:
The issue is related to the incorrect session expiration in the JetBrains TeamCity CI/CD system. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. In JetBrains TeamCity, access tokens were not revoked after removing user roles, which could lead to unauthorized access.
Recommendations:
For versions prior to 2024.12, update to version 2024.12 or later to ensure access tokens are properly revoked after user roles are removed. As a temporary workaround, consider manually revoking access tokens after removing user roles to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetbrains Teamcity
Teamcity