CVE-2024-36367
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published May 29, 2024
Updated: May 31, 2024
CWE ID 79
Summary
CVE-2024-36367 is a stored Cross-Site Scripting (XSS) vulnerability affecting JetBrains TeamCity versions before 2022.04.7, 2022.10.6, 2023.05.6, and 2023.11.5. Malicious third-party reports could be used to inject malicious scripts into the application, potentially leading to unauthorized access or data theft when users view the reports. This vulnerability poses a significant risk to organizations using the affected versions of TeamCity and emphasizes the importance of keeping software up-to-date to mitigate known security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share