Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2024-56353
Summary
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- HIGH
- HIGH
- NONE
CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
References
Advisory Timeline
- Published