CVE-2019-15042: High severity jetbrains teamcity vulnerability
Published Oct 1, 2019
·Updated
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
Affected Software
1 affected component
JetBrains TeamCity=2018.2.4
Event History
Oct 1, 2019
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15042?
CVE-2019-15042 is considered a moderate severity vulnerability due to improper SSL certificate validation.
2
How do I fix CVE-2019-15042?
To fix CVE-2019-15042, upgrade JetBrains TeamCity to version 2019.1 or later.
3
What versions of JetBrains TeamCity are affected by CVE-2019-15042?
JetBrains TeamCity version 2018.2.4 is affected by CVE-2019-15042.
4
What type of vulnerability is CVE-2019-15042?
CVE-2019-15042 is a SSL certificate validation vulnerability.
5
Is there a workaround for CVE-2019-15042?
There is no recommended workaround for CVE-2019-15042; upgrading to a secure version is the best option.