PT-2024-1520 · Jetbrains · Jetbrains Teamcity+1

Published

2024-02-06

·

Updated

2025-01-03

·

CVE-2024-23917

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions 2017.1 through 2023.11.2
Description The issue is related to an authentication bypass in JetBrains TeamCity, which can lead to remote code execution (RCE). This allows an unauthenticated attacker with HTTP(S) access to gain administrative control over a TeamCity server. Over 1000 instances of JetBrains TeamCity are vulnerable to this attack.
Recommendations For versions 2017.1 through 2023.11.2, update to version 2023.11.3 or apply a security patch plugin to fix the authentication bypass vulnerability. As a temporary workaround, consider restricting access to the TeamCity server until the update or patch can be applied.

Fix

RCE

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2024-01032
CVE-2024-23917

Affected Products

Jetbrains Teamcity
Teamcity