QID 379074
Date Published: 2023-12-26
QID 379074: JetBrains TeamCity Multiple Security Vulnrabilities (TW-82485,TW-82283,TW-82472)
JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.
CVE-2023-39173: A token with limited permissions could be used to gain full account access
CVE-2023-39174: A ReDoS attack was possible via integration with issue trackers
CVE-2023-39175: Reflected XSS via GitHub integration was possible
Affected Versions :
TeamCity prior to 2023.05.2
QID Detection Logic(Authenticated and Unauthenticated):
QID checks for vulnerable version of installed TeamCity in the System
Successful exploitation of this vulnerability may affect Confidentiality and Integrity of the data.
Solution
Customers are advised to refer to JetBrains vendor advisory JetBrains TeamCity Security Advisory (TW-82867, TW-82475, TW-82869, TW-82876) for further information on this vulnerability.
Vendor References
- JetBrains TeamCity -
www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity
CVEs related to QID 379074
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity |
|