CVE-2024-36362

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

History

16 Dec 2024, 15:41

Type Values Removed Values Added
References () https://www.jetbrains.com/privacy-security/issues-fixed/ - () https://www.jetbrains.com/privacy-security/issues-fixed/ - Vendor Advisory
First Time Jetbrains teamcity
Jetbrains
CWE CWE-22
CPE cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

21 Nov 2024, 09:22

Type Values Removed Values Added
References () https://www.jetbrains.com/privacy-security/issues-fixed/ - () https://www.jetbrains.com/privacy-security/issues-fixed/ -

31 May 2024, 14:15

Type Values Removed Values Added
Summary
  • (es) En JetBrains TeamCity antes de 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5, 2024.03.2 era posible path traversal permitiendo leer archivos del servidor
Summary (en) In JetBrains TeamCity before 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible (en) In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

29 May 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-29 14:15

Updated : 2024-12-16 15:41


NVD link : CVE-2024-36362

Mitre link : CVE-2024-36362

CVE.ORG link : CVE-2024-36362


JSON object : View

Products Affected

jetbrains

  • teamcity
CWE
CWE-23

Relative Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')