Stored XSS Vulnerability in JetBrains TeamCity
CVE-2023-38065
4.6MEDIUM
What is CVE-2023-38065?
A stored Cross-Site Scripting (XSS) vulnerability was found in JetBrains TeamCity, allowing attackers to inject malicious scripts via the build log feature. This flaw affects TeamCity versions prior to 2023.05.1 and can enable an unauthorized user to execute scripts in the context of another user’s session, potentially compromising data integrity and user security.
Affected Version(s)
TeamCity 0 < 2023.05.1
References
EPSS Score
50% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved