QID 379073

Date Published: 2023-12-26

QID 379073: JetBrains TeamCity Multiple Security Vulnrabilities (TW-82867,TW-82475,TW-82869,TW-82876)

JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.

CVE-2023-41248: Stored XSS was possible during Cloud Profiles configuration.
CVE-2023-41249: Reflected XSS was possible during copying Build Step.
CVE-2023-41250: Reflected XSS was possible during user registration.

Affected Versions :
TeamCity prior to 2023.05.3

QID Detection Logic(Authenticated and Unauthenticated):
QID checks for vulnerable version of installed TeamCity in the System

Successful exploitation of this vulnerability may affect Confidentiality and Integrity of the data.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to refer to JetBrains vendor advisory JetBrains TeamCity Security Advisory (TW-82867, TW-82475, TW-82869, TW-82876) for further information on this vulnerability.

    CVEs related to QID 379073

    Software Advisories
    Advisory ID Software Component Link
    JetBrains TeamCity URL Logo www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity