Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
References
Link | Resource |
---|---|
https://blog.jetbrains.com/blog/2019/09/26/jetbrains-security-bulletin-q2-2019/ | Vendor Advisory |
Configurations
Information
Published : 2019-10-02 12:15
Updated : 2021-11-04 07:28
NVD link : CVE-2019-12156
Mitre link : CVE-2019-12156
JSON object : View
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
Products Affected
jetbrains
- upsource