QID 375386
Date Published: 2021-03-23
QID 375386: JetBrains TeamCity Cross-site Scripting Vulnerability
JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
Affected Versions :
JetBrains TeamCity 2019.1 and 2019.1.1
QID Detection Logic(Authenticated)
This checks for vulnerable version of TeamCity.
On successful exploitation it allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
Solution
Update to the latest version of JetBrains TeamCity.
Vendor References
CVEs related to QID 375386
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity | Linux |
|