Vulnerability record · CVE-2022-48428 · published 27 March 2023
CVE-2022-48428: JetBrains TeamCity stored XSS on SSH keys page
Jetbrains · Teamcity
JetBrains TeamCity before 2022.10.3 contains a stored cross-site scripting flaw on the SSH keys page. Because the payload persists in the application and is served to other users, it can execute in their browsers when they view the affected page. The record does not specify the exact vulnerable input or the versions beyond the fixed release.
Description
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityStored XSS in a CI server can affect privileged users, but it requires authentication and user interaction and no active exploitation is documented.
What it is
JetBrains TeamCity before 2022.10.3 contains a stored cross-site scripting flaw on the SSH keys page. Because the payload persists in the application and is served to other users, it can execute in their browsers when they view the affected page. The record does not specify the exact vulnerable input or the versions beyond the fixed release.
Impact
An attacker can run script in the browser context of a victim who views the SSH keys page, potentially stealing session data or performing actions as that user. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
The flaw is network reachable and requires the attacker to be authenticated with low privileges, while a victim must interact with the crafted content. No further detail on the exact injection point is provided.
Exploitation
Not listed in CISA KEV and no public exploit reference is given, but EPSS is high at roughly 0.68 probability (99th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Upgrade TeamCity to 2022.10.3 or later, which is the fixed release named in the advisory.
- Restrict access to the SSH keys page to trusted administrators and review who holds low-privilege accounts.
- Apply output encoding and input sanitization for user-supplied content rendered on the SSH keys page.
- Enforce a strict Content Security Policy to limit script execution in the TeamCity UI.
Detection
- Review TeamCity web logs for suspicious requests to the SSH keys page containing script tags or encoded payloads.
- Monitor for unexpected script execution or anomalous browser-side activity reported by users of the SSH keys page.
- Audit SSH key entries and page content for injected markup or unexpected changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Issue TrackingVendor Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Issue TrackingVendor Advisory |
Track CVE-2022-48428 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-48428), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.