CVE-2023-34219
MEDIUMCVSS 4.3/10EPSS 0.35%
Last modified
CVE-2023-34219 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jetbrains | Teamcity | < 2023.05 |
References
- https://www.jetbrains.com/privacy-security/issues-fixed/Vendor Advisory
- https://www.jetbrains.com/privacy-security/issues-fixed/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-34219?
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
How severe is CVE-2023-34219?
CVE-2023-34219 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2023-34219?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-34213TN-5900 Series firmware versions v3.3 and prior are vulnerab…9.8
- CVE-2023-34214TN-4900 Series firmware versions v1.2.4 and prior and TN-590…9.8
- CVE-2023-34215TN-5900 Series firmware versions v3.3 and prior are vulnerab…9.8
- CVE-2023-34216TN-4900 Series firmware versions v1.2.4 and prior and TN-590…8.1
- CVE-2023-34217TN-4900 Series firmware versions v1.2.4 and prior and TN-590…8.1
- CVE-2023-34218In JetBrains TeamCity before 2023.05 bypass of permission ch…9.8
- CVE-2023-3422Use after free in Guest View in Google Chrome prior to 114.0…8.8
- CVE-2023-34220In JetBrains TeamCity before 2023.05 stored XSS in the Commi…5.4
- CVE-2023-34221In JetBrains TeamCity before 2023.05 stored XSS in the Show …5.4
- CVE-2023-34222In JetBrains TeamCity before 2023.05 possible XSS in the Plu…6.1
- CVE-2023-34223In JetBrains TeamCity before 2023.05 parameters of the "pass…5.3
- CVE-2023-34224In JetBrains TeamCity before 2023.05 open redirect during oA…4.8
Are you affected by CVE-2023-34219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
