JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-06-29T14:07:44.700Z

Updated: 2024-08-06T04:40:18.192Z

Reserved: 2015-01-22T00:00:00.000Z

Link: CVE-2015-1313

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-06-29T15:15:09.190

Modified: 2023-07-06T18:25:35.530

Link: CVE-2015-1313

cve-icon Redhat

No data.