Stored XSS Vulnerability in JetBrains TeamCity Affecting Agent Details Page
CVE-2024-56352

5.4MEDIUM

Key Information:

Vendor
JetBrains
Status
Vendor
CVE Published:
20 December 2024

Summary

CVE-2024-56352 exposes JetBrains TeamCity to a stored cross-site scripting (XSS) vulnerability. This flaw allows an attacker to inject malicious scripts through manipulated image names on the agent details page. When this page is accessed, the embedded scripts can execute in the context of the user's session, potentially leading to unauthorized actions or data exposure. Organizations using affected TeamCity versions should prioritize applying available security updates to mitigate the risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.