JetBrains TeamCity 8 and 9 prior to 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jetbrains teamcity |