CVE-2024-36371

In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
References
Link Resource
https://www.jetbrains.com/privacy-security/issues-fixed/ Issue Tracking Vendor Advisory
https://www.jetbrains.com/privacy-security/issues-fixed/ Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

History

07 Feb 2025, 20:11

Type Values Removed Values Added
First Time Jetbrains
Jetbrains teamcity
References () https://www.jetbrains.com/privacy-security/issues-fixed/ - () https://www.jetbrains.com/privacy-security/issues-fixed/ - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

31 May 2024, 14:15

Type Values Removed Values Added
Summary In JetBrains TeamCity before 2023.05.5, 2023.11.5 stored XSS in Commit status publisher was possible In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible

29 May 2024, 15:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-29 14:15

Updated : 2025-02-07 20:11


NVD link : CVE-2024-36371

Mitre link : CVE-2024-36371


JSON object : View

Products Affected

jetbrains

  • teamcity
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')