CVE-2023-39173

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jul 25, 2023
Updated: Aug 1, 2023
CWE ID 266

Summary

CVE-2023-39173 is a vulnerability affecting JetBrains TeamCity prior to version 2023.05.2. In this issue, a token with restricted permissions could be exploited to grant an attacker unauthorized full account access, posing a significant risk to the security of TeamCity instances. This vulnerability could potentially allow attackers to make changes to the system configuration, modify or steal data, and even gain control of other connected systems. It is recommended that affected users immediately update to the latest version of TeamCity to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share