Vulnerability record · CVE-2023-34220 · published 31 May 2023
CVE-2023-34220: JetBrains TeamCity stored XSS in Commit Status Publisher window
Jetbrains · Teamcity
JetBrains TeamCity before 2023.05 contains a stored cross-site scripting flaw in the Commit Status Publisher window. Because the payload is stored, it can persist and execute in the browser of any user who views the affected window, which matters for a CI server where sessions often carry build and administrative privileges.
Description
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, but the high EPSS score and stored nature in a CI server raise the practical risk.
What it is
JetBrains TeamCity before 2023.05 contains a stored cross-site scripting flaw in the Commit Status Publisher window. Because the payload is stored, it can persist and execute in the browser of any user who views the affected window, which matters for a CI server where sessions often carry build and administrative privileges.
Impact
An attacker can execute script in the context of a victim's TeamCity session, potentially reading data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the TeamCity web interface, specifically the Commit Status Publisher window. The vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated low-privileged user must get a victim to view the crafted content.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, which are vendor advisories only. EPSS is high at 0.61173 (99.12th percentile), suggesting elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Upgrade TeamCity to 2023.05 or later, which contains the fix per the vendor advisory.
- Restrict who can configure or interact with the Commit Status Publisher window to trusted users.
- Apply output encoding and input sanitization for stored content in the Commit Status Publisher window if backporting.
- Enforce a strict Content Security Policy to limit script execution in the TeamCity UI.
- Review TeamCity accounts and remove unnecessary low-privileged access.
Detection
- Search TeamCity logs and audit trails for unexpected changes to Commit Status Publisher configuration or commit status entries.
- Monitor for suspicious script content or HTML payloads stored in commit status fields and related build metadata.
- Inspect web access logs for requests to the Commit Status Publisher window from unusual accounts or patterns.
- Watch for anomalous authenticated session activity, such as actions taken shortly after viewing the Commit Status Publisher window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Track CVE-2023-34220 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34220), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.