CVE-2023-34223
MEDIUMCVSS 5.3/10EPSS 1.33%
Last modified
CVE-2023-34223 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases. EPSS estimates a 1.33% chance of exploitation in the next 30 days.
Description
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jetbrains | Teamcity | < 2023.05 |
References
- https://www.jetbrains.com/privacy-security/issues-fixed/Vendor Advisory
- https://www.jetbrains.com/privacy-security/issues-fixed/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-34223?
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
How severe is CVE-2023-34223?
CVE-2023-34223 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 1.33% probability of exploitation in the next 30 days.
How do I fix CVE-2023-34223?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-34218In JetBrains TeamCity before 2023.05 bypass of permission ch…9.8
- CVE-2023-34219In JetBrains TeamCity before 2023.05 improper permission che…4.3
- CVE-2023-3422Use after free in Guest View in Google Chrome prior to 114.0…8.8
- CVE-2023-34220In JetBrains TeamCity before 2023.05 stored XSS in the Commi…5.4
- CVE-2023-34221In JetBrains TeamCity before 2023.05 stored XSS in the Show …5.4
- CVE-2023-34222In JetBrains TeamCity before 2023.05 possible XSS in the Plu…6.1
- CVE-2023-34224In JetBrains TeamCity before 2023.05 open redirect during oA…4.8
- CVE-2023-34225In JetBrains TeamCity before 2023.05 stored XSS in the NuGet…5.4
- CVE-2023-34226In JetBrains TeamCity before 2023.05 reflected XSS in the Su…6.1
- CVE-2023-34227In JetBrains TeamCity before 2023.05 a specific endpoint was…7.5
- CVE-2023-34228In JetBrains TeamCity before 2023.05 authentication checks w…6.5
- CVE-2023-34229In JetBrains TeamCity before 2023.05 stored XSS in GitLab Co…5.4
Are you affected by CVE-2023-34223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
