CVE-2024-36362

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

History

16 Dec 2024, 15:41

Type Values Removed Values Added
CWE CWE-22
References () https://www.jetbrains.com/privacy-security/issues-fixed/ - () https://www.jetbrains.com/privacy-security/issues-fixed/ - Vendor Advisory
First Time Jetbrains
Jetbrains teamcity
CPE cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

31 May 2024, 14:15

Type Values Removed Values Added
Summary In JetBrains TeamCity before 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

29 May 2024, 15:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-29 14:15

Updated : 2024-12-16 15:41


NVD link : CVE-2024-36362

Mitre link : CVE-2024-36362


JSON object : View

Products Affected

jetbrains

  • teamcity
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')