8.8
CVSSv3

CVE-2022-24342

Published: 25/02/2022 Updated: 04/03/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In JetBrains TeamCity prior to 2021.2.1, URL injection leading to CSRF was possible.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jetbrains teamcity

Github Repositories

PoC for CVE-2022-24342: account takeover via CSRF in GitHub authentication

CVE-2022-24342 JetBrains TeamCity - account takeover via CSRF in GitHub authentication (PoC) CVE-2022-24342 Requirements Usage How does it work? GitHub OAuth2: query parameters processing order CVE-2022-24342: HTTP requests flow Requirements JetBrains TeamCity <202121 GitHub authentication enabled Usage Try to login with attacker's GitHub account int