Vulnerability record · CVE-2023-41249 · published 25 August 2023
CVE-2023-41249: JetBrains TeamCity reflected XSS in Build Step copying
Jetbrains · Teamcity
JetBrains TeamCity before 2023.05.3 is vulnerable to reflected cross-site scripting during the copying of a Build Step. Because the flaw is reflected and requires a victim to interact, it matters mainly as a way to run script in a logged-in user's browser session.
Description
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) and it requires user interaction, but the very high EPSS percentile warrants prompt patching.
What it is
JetBrains TeamCity before 2023.05.3 is vulnerable to reflected cross-site scripting during the copying of a Build Step. Because the flaw is reflected and requires a victim to interact, it matters mainly as a way to run script in a logged-in user's browser session.
Impact
An attacker can execute arbitrary script in the context of a TeamCity user's browser, potentially stealing session data or performing actions as that user. The CVSS scope change indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted request tied to the Build Step copy function; no authentication is required by the attacker, but the victim must interact with a malicious link or page (UI:R).
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.555 (99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade TeamCity to 2023.05.3 or later, which the vendor states fixes this issue.
- If immediate upgrade is not possible, restrict network access to the TeamCity web interface to trusted users and networks.
- Instruct users not to follow untrusted links into TeamCity and to log out of sessions when not in use.
- Apply output encoding and input validation for the Build Step copy functionality if customizing or extending the product.
Detection
- Review TeamCity web access logs for requests to Build Step copy endpoints containing script-like payloads or unusual encoded characters.
- Monitor for anomalous authenticated actions or session activity following visits to crafted TeamCity URLs.
- Check browser or proxy logs for reflected script content in responses from the TeamCity interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Track CVE-2023-41249 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-41249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.