CVE-2024-56355

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 20, 2024
Updated: Jan 2, 2025
CWE ID 79

Summary

CVE-2024-56355 is a newly disclosed cybersecurity vulnerability affecting JetBrains TeamCity. This issue arises from a missing Content-Type header in responses from the RemoteBuildLogController, which could pave the way for Cross-Site Scripting (XSS) attacks. An attacker, upon successfully exploiting this flaw, could inject malicious scripts into a victim's browser, potentially leading to data theft or unauthorized access. Upgrading to TeamCity 2024.12 or applying the relevant patch is recommended to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share