First published: Thu May 16 2024(Updated: )
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2024.03.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35301 is rated as a high severity vulnerability.
To fix CVE-2024-35301, upgrade JetBrains TeamCity to version 2024.03.1 or later.
CVE-2024-35301 affects JetBrains TeamCity versions before 2024.03.1.
CVE-2024-35301 is a role-based access control vulnerability.
If unable to upgrade, evaluate the exposure and minimize the use of the affected features until an upgrade is possible.