CVE-2024-28174

CVSS 3.1 Score 5.8 of 10 (medium)

Details

Published Mar 6, 2024
Updated: Dec 16, 2024
CWE ID 863

Summary

CVE-2024-28174 is a cybersecurity vulnerability affecting JetBrains TeamCity versions prior to 2023.11.4. This issue involves the S3 Artifact Storage plugin, where presigned URL generation requests were incorrectly authorized. An attacker could potentially exploit this flaw to gain unauthorized access to S3 artifacts, leading to data leakage or other malicious activities. It's essential for TeamCity users to update their software to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share