Vulnerability record · CVE-2022-48343 · published 23 February 2023
CVE-2022-48343: JetBrains TeamCity XSS in user creation process
Jetbrains · Teamcity
JetBrains TeamCity before 2022.10.2 contains a cross-site scripting flaw in the user creation process. Because the injected script runs in the context of the TeamCity web UI, it can act on behalf of users who view the affected page. The record gives no further detail on the exact injection point or required fields.
Description
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) with user interaction required, but the very high EPSS percentile warrants prompt patching.
What it is
JetBrains TeamCity before 2022.10.2 contains a cross-site scripting flaw in the user creation process. Because the injected script runs in the context of the TeamCity web UI, it can act on behalf of users who view the affected page. The record gives no further detail on the exact injection point or required fields.
Impact
An attacker can execute script in a victim's browser session, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via the TeamCity web interface; the vector shows no privileges required (PR:N) but user interaction is required (UI:R), so a victim must open or interact with crafted content. No authentication is needed to deliver the attack.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS is high at roughly 0.59 (99th percentile), suggesting elevated likelihood of exploitation activity even though no confirmed in-the-wild use is documented here.
What to do
- Upgrade TeamCity to 2022.10.2 or later, which the vendor states fixes this issue.
- If immediate upgrade is not possible, restrict network access to the TeamCity web UI to trusted users and networks.
- Apply output encoding and input validation to user-supplied fields in the user creation workflow as a defense-in-depth measure.
- Deploy a content security policy that limits inline script execution in the TeamCity UI.
- Monitor vendor advisories for any follow-up guidance on this issue.
Detection
- Review TeamCity web server and application logs for suspicious script payloads or encoded characters in user creation requests.
- Search for unexpected or injected script content in user profile and user creation fields within TeamCity.
- Monitor for anomalous authenticated sessions or actions originating shortly after user creation events.
- Use web application firewall or proxy logs to flag XSS-style payloads targeting TeamCity endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Track CVE-2022-48343 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-48343), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.