Stored XSS Vulnerability in JetBrains TeamCity Affecting Agent Details Page
CVE-2024-56352
5.4MEDIUM
Summary
CVE-2024-56352 exposes JetBrains TeamCity to a stored cross-site scripting (XSS) vulnerability. This flaw allows an attacker to inject malicious scripts through manipulated image names on the agent details page. When this page is accessed, the embedded scripts can execute in the context of the user's session, potentially leading to unauthorized actions or data exposure. Organizations using affected TeamCity versions should prioritize applying available security updates to mitigate the risk.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published