CVE-2023-38062: Infoleak
Published Jul 12, 2023
·Updated
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
Affected Software
1 affected component
JetBrains TeamCity<2023.05.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2023.05.1
Event History
Jul 12, 2023
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38062.
2
What is the severity of CVE-2023-38062?
The severity of CVE-2023-38062 is medium.
3
What is the affected software?
The affected software is JetBrains TeamCity before version 2023.05.1.
4
What is the impact of CVE-2023-38062?
The impact of CVE-2023-38062 is that parameters of the 'password' type could be shown in the UI in certain composite build configurations.
5
How can I fix CVE-2023-38062?
To fix CVE-2023-38062, update JetBrains TeamCity to version 2023.05.1 or higher.