CVE-2023-34219: Medium severity JetBrains TeamCity vulnerability
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2023.05
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-34219.
What is the severity rating of CVE-2023-34219?
The severity rating of CVE-2023-34219 is medium.
What is the description of CVE-2023-34219?
CVE-2023-34219 is a vulnerability in JetBrains TeamCity before 2023.05 that allows users without appropriate permissions to edit Build Configuration settings via REST API due to improper permission checks.
Which software versions are affected by CVE-2023-34219?
JetBrains TeamCity versions up to and excluding 2023.05 are affected by CVE-2023-34219.
How can I fix CVE-2023-34219?
To fix CVE-2023-34219, it is recommended to update JetBrains TeamCity to version 2023.05 or later.