QID 379074

Date Published: 2023-12-26

QID 379074: JetBrains TeamCity Multiple Security Vulnrabilities (TW-82485,TW-82283,TW-82472)

JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.

CVE-2023-39173: A token with limited permissions could be used to gain full account access
CVE-2023-39174: A ReDoS attack was possible via integration with issue trackers
CVE-2023-39175: Reflected XSS via GitHub integration was possible

Affected Versions :
TeamCity prior to 2023.05.2

QID Detection Logic(Authenticated and Unauthenticated):
QID checks for vulnerable version of installed TeamCity in the System

Successful exploitation of this vulnerability may affect Confidentiality and Integrity of the data.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to JetBrains vendor advisory JetBrains TeamCity Security Advisory (TW-82867, TW-82475, TW-82869, TW-82876) for further information on this vulnerability.

    CVEs related to QID 379074

    Software Advisories
    Advisory ID Software Component Link
    JetBrains TeamCity URL Logo www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity