QID 379072
Date Published: 2023-12-26
QID 379072: JetBrains TeamCity Stored Cross-Site Scripting (XSS) Vulnerability (TW-83216)
JetBrains TeamCity is a continuous integration server that can build, test, and release software.
In JetBrains TeamCity Stored XSS was possible during nodes configuration.
Affected Versions:
JetBrains TeamCity prior to 2023.05.4
QID Detection Logic:
This QID detects the vulnerable version by checking the JetBrains TeamCity file version.
Successful exploitation of this vulnerability may affect Confidentiality and Integrity of the data.
Solution
Customers are advised to refer to JetBrains vendor advisory TeamCity Security Advisory (TW-83216) for further information on this vulnerability.
Vendor References
- JetBrains TeamCity -
www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity
CVEs related to QID 379072
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity |
|