In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
https://blog.jetbrains.com | vendor advisory |
https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021/ | vendor advisory |