Stored XSS vulnerability in TeamCity Clouds page
CVE-2024-43807

5.4MEDIUM

Key Information:

Vendor

JetBrains

Status
Vendor
CVE Published:
16 August 2024

What is CVE-2024-43807?

A vulnerability exists in JetBrains TeamCity, specifically affecting versions released prior to 2024.07.1. This issue involves multiple stored cross-site scripting (XSS) vulnerabilities present on the Clouds page. Attackers can exploit these vulnerabilities to inject malicious scripts, potentially compromising user data and session integrity. Effective mitigation strategies and updates are essential for maintaining the security of user interactions within the JetBrains TeamCity environment.

References

EPSS Score

13% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.