PT-2024-1520 · Jetbrains · Jetbrains Teamcity+1
Published
2024-02-06
·
Updated
2025-01-03
·
CVE-2024-23917
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JetBrains TeamCity versions 2017.1 through 2023.11.2
Description
The issue is related to an authentication bypass in JetBrains TeamCity, which can lead to remote code execution (RCE). This allows an unauthenticated attacker with HTTP(S) access to gain administrative control over a TeamCity server. Over 1000 instances of JetBrains TeamCity are vulnerable to this attack.
Recommendations
For versions 2017.1 through 2023.11.2, update to version 2023.11.3 or apply a security patch plugin to fix the authentication bypass vulnerability. As a temporary workaround, consider restricting access to the TeamCity server until the update or patch can be applied.
Fix
RCE
Missing Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetbrains Teamcity
Teamcity