PT-2024-9849 · Jetbrains · Teamcity

CVE-2024-56352

·

Published

2024-12-20

·

Updated

2025-01-02

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: JetBrains TeamCity versions prior to 2024.12
Description: The issue allows for stored Cross Site Scripting (XSS) via the image name on the agent details page. This can be exploited by a remote attacker to conduct an inter-site scripting attack.
Recommendations: For versions prior to 2024.12, update to version 2024.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the agent details page until a patch is available. Avoid using the image name field in the agent details page until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11627
CVE-2024-56352

Affected Products

Teamcity