First published: Wed May 31 2023(Updated: )
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2023.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-34219.
The severity rating of CVE-2023-34219 is medium.
CVE-2023-34219 is a vulnerability in JetBrains TeamCity before 2023.05 that allows users without appropriate permissions to edit Build Configuration settings via REST API due to improper permission checks.
JetBrains TeamCity versions up to and excluding 2023.05 are affected by CVE-2023-34219.
To fix CVE-2023-34219, it is recommended to update JetBrains TeamCity to version 2023.05 or later.