Stored XSS Vulnerability in JetBrains TeamCity
CVE-2023-38065

4.6MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
12 July 2023

What is CVE-2023-38065?

A stored Cross-Site Scripting (XSS) vulnerability was found in JetBrains TeamCity, allowing attackers to inject malicious scripts via the build log feature. This flaw affects TeamCity versions prior to 2023.05.1 and can enable an unauthorized user to execute scripts in the context of another user’s session, potentially compromising data integrity and user security.

Affected Version(s)

TeamCity 0 < 2023.05.1

References

EPSS Score

50% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.