Описание
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2021.2.1 (исключая)
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00004
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-367
Связанные уязвимости
github
почти 4 года назад
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
EPSS
Процентиль: 0%
0.00004
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-367