Information Disclosure in JetBrains TeamCity and UpSource
CVE-2019-12156
5.3MEDIUM
What is CVE-2019-12156?
This vulnerability allows an attacker to potentially expose sensitive server metadata, as one of the error messages inadvertently reflects the entire response back to the client in certain versions of JetBrains TeamCity and UpSource. Specifically, versions prior to 2018.2.5 for TeamCity and versions prior to 2018.2 build 1293 for UpSource are impacted. Proper validation and error handling mechanisms need to be in place to prevent such exposure.