CVE-2024-28174
CVSS 3.1 Score 5.8 of 10 (medium)
Details
Published Mar 6, 2024
Updated: Dec 16, 2024
CWE ID 863
Summary
CVE-2024-28174 is a cybersecurity vulnerability affecting JetBrains TeamCity versions prior to 2023.11.4. This issue involves the S3 Artifact Storage plugin, where presigned URL generation requests were incorrectly authorized. An attacker could potentially exploit this flaw to gain unauthorized access to S3 artifacts, leading to data leakage or other malicious activities. It's essential for TeamCity users to update their software to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- TeamCity
Affected Vendors
- JetBrains