Cyber Resilience

CVE-2024-41828

Jetbrains Teamcity ≤ 2024.07

Published
22 July 2024
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 2.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.0028 21th percentile
Risk Priority 15 floored blend · peak EPSS

Summary

CVE-2024-41828 is a low-severity Observable Timing Discrepancy (CWE-208) vulnerability in Jetbrains Teamcity. Its CVSS base score is 2.6 (Low).

Operationally, ranked at the 21th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-39175Same product: Jetbrains Teamcity
CVE-2025-54538Same product: Jetbrains Teamcity
CVE-2024-47950Same product: Jetbrains Teamcity
CVE-2024-39879Same product: Jetbrains Teamcity
CVE-2023-38067Same product: Jetbrains Teamcity
CVE-2026-49376Same product: Jetbrains Teamcity
CVE-2024-36366Same product: Jetbrains Teamcity
CVE-2025-54530Same product: Jetbrains Teamcity
CVE-2025-54536Same product: Jetbrains Teamcity
CVE-2025-54532Same product: Jetbrains Teamcity

Affected Assets

jetbrains
teamcity
≤ 2024.07

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V11.2.4

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-208

Timing randomization or delays can mask true operation timing and mislead timing-based attacks.

addresses: CWE-208

Observable timing discrepancies are a primary mechanism for constructing covert timing channels; analysis identifies and bounds them, limiting exploitation.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly require constant-time implementations that eliminate observable timing discrepancies.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

Consistent reference clocks limit the attacker's ability to measure or manipulate timing differences that could reveal internal state or processing paths.

References