JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.jetbrains.com/teamcity/2019/09/important-security-notice-xss-vulnerability-allowing-rce/ - Patch, Vendor Advisory | |
References | () https://gist.github.com/JLLeitschuh/fe6784391254b58de680bbda78a04a70 - | |
References | () https://twitter.com/JLLeitschuh/status/1169332316612644864?s=20 - | |
References | () https://www.softwaresecured.com/jetbrains-teamcity-reflected-xss/ - |
Information
Published : 2019-09-05 20:15
Updated : 2024-11-21 04:29
NVD link : CVE-2019-15848
Mitre link : CVE-2019-15848
CVE.ORG link : CVE-2019-15848
JSON object : View
Products Affected
jetbrains
- teamcity
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')