CVE-2024-36372
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2024-36372 is a newly disclosed vulnerability affecting JetBrains TeamCity versions prior to 2023.05.6. This issue permits an attacker to execute Reflected Cross-Site Scripting (XSS) attacks on the subscriptions page, potentially leading to unintended execution of malicious scripts in users' browsers. The vulnerability poses a serious security risk, especially in enterprise environments where TeamCity is used for continuous integration and continuous delivery. Successful exploitation could result in data theft, unauthorized access, or other malicious activities. Users are strongly encouraged to update their TeamCity installations as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.