TeamCity Vulnerable to DoS Attacks via Incorrect Auth Tokens
CVE-2024-36378

7.5HIGH

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
29 May 2024

Summary

JetBrains TeamCity server prior to version 2024.03.2 is vulnerable to denial of service (DoS) attacks due to improper handling of authentication tokens. Attackers can exploit this vulnerability to disrupt the availability of the TeamCity server, potentially causing downtime and impacting build and deployment processes. It is crucial for users to upgrade to the latest version to protect their systems and maintain uninterrupted service.

Affected Version(s)

TeamCity 0 < 2024.03.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.