spring4shell vulnerability

Is the latest TeamCity vulnerable to the spring4shell ZD RCE? 

If so how do I handle this

0
2 comments

Hi Allan,

 

it is not. Our investigation showed that the vulnerability requires some features to be exploitable that TeamCity does not use. You can check more details in our issue in the tracker, feel free to follow it to stay up to date if there are new developments on the issue: https://youtrack.jetbrains.com/issue/TW-75604

1

Great, thanks for quick answer :-)

0

Please sign in to leave a comment.