First published: Wed May 29 2024(Updated: )
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | <2024.03.2 | |
Jetbrains Teamcity | <2024.03.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36377 is rated as a critical vulnerability due to inadequate permission checks in TeamCity API endpoints.
To remediate CVE-2024-36377, update JetBrains TeamCity to version 2024.03.2 or later.
CVE-2024-36377 affects JetBrains TeamCity versions prior to 2024.03.2.
Exploitation of CVE-2024-36377 could allow unauthorized users to access sensitive data through the API.
If unable to update, restrict access to the vulnerable TeamCity API endpoints until a fix can be applied.