Vulnerability record · CVE-2023-34225 · published 31 May 2023
CVE-2023-34225: JetBrains TeamCity NuGet feed page stored XSS
Jetbrains · Teamcity
JetBrains TeamCity before 2023.05 contains a stored cross-site scripting flaw in the NuGet feed page. Because the payload is stored server-side, it can be served to other users who view the affected page, making it more than a self-only issue. The record gives no further detail on the vulnerable parameter or the exact injection point.
Description
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityStored XSS with scope change and a high EPSS score, but it requires authentication and user interaction and has no confirmed exploitation.
What it is
JetBrains TeamCity before 2023.05 contains a stored cross-site scripting flaw in the NuGet feed page. Because the payload is stored server-side, it can be served to other users who view the affected page, making it more than a self-only issue. The record gives no further detail on the vulnerable parameter or the exact injection point.
Impact
An attacker can execute script in the browser context of a victim who views the NuGet feed page, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network via the TeamCity web interface; the vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated low-privileged user must get a victim to view the crafted content. No unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tag appears in the references, which are vendor advisories only. EPSS is high (0.6072, 99.1st percentile), suggesting elevated predicted likelihood, but this is a model estimate, not confirmed exploitation.
What to do
- Upgrade TeamCity to 2023.05 or later, which the vendor states fixes this issue.
- If immediate upgrade is not possible, restrict access to the NuGet feed page to trusted users and review who holds feed-write permissions.
- Apply output encoding and input sanitization to any user-supplied content rendered on the NuGet feed page.
- Enforce a strict Content-Security-Policy to limit script execution in the TeamCity UI.
- Review and reduce low-privileged accounts that can post content to feeds.
Detection
- Search TeamCity and reverse-proxy logs for suspicious script payloads in requests to NuGet feed endpoints.
- Monitor for unexpected script tags or event-handler attributes in stored feed content and database records.
- Alert on anomalous authenticated sessions or actions following a feed page view by a privileged user.
- Review browser-side alerts for inline script execution on TeamCity feed pages if client telemetry is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Track CVE-2023-34225 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34225), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.