On-premises JetBrains TeamCity servers vulnerable to auth bypass (CVE-2024-23917)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-42793 | Authentication bypass in JetBrains TeamCity enables unauthenticated RCE JetBrains TeamCity Server, a widely used CI/CD build server, contains an authentication bypass vulnerability (CWE-288) that lets a remote, unauthenticated attacker gain administrative access without valid credentials. By sending crafted requests to the TeamCity server over the network, the attacker bypasses authentication and can then execute arbitrary code on the server via administrative and build features, achieving full remote code execution. An attacker gains control of the build server and, with it, access to source code, build artifacts, stored secrets and credentials, and a foothold for lateral movement or ransomware deployment. Any organization running an affected TeamCity Server is affected, especially instances reachable from the internet. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2023-10-04 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Upgrade TeamCity Server to 2023.05.4 or later per JetBrains' instructions, or apply vendor mitigations or discontinue use if patching is not possible (per the CISA KEV required action). Also take unpatched instances off the public internet, and hunt for signs of compromise such as unauthorized administrator accounts, unexpected changes in audit logs and build configurations, and stored secrets or tokens that may have been stolen, given known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largeTens of thousands of TeamCity Server deployments, of which several thousand are internet-exposed | |
| CVE-2024-23917 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible NVD description · AI analysis pending | 9.8 | 54% |
| — |
Full article244 words · extracted from helpnetsecurity.com · click to collapse
JetBrains has patched a critical authentication bypass vulnerability (CVE-2024-23917) affecting TeamCity On-Premises continuous integration and deployment servers.

About CVE-2024-23917
CVE-2024-23917 could allow an unauthenticated threat actor with HTTP(S) access to a TeamCity server to bypass authentication controls and gain administrative privileges on the server.
The vulnerability was first identified and reported by an external security researcher on January 19, 2024, and affects all versions of TeamCity On-Premises from 2017.1 through 2023.11.2.
“We have fixed this vulnerability in version 2023.11.3 and have already notified our customers. We will also release additional technical details of the vulnerability shortly. In the meantime, we strongly advise all TeamCity On-Premises users to update their servers to 2023.11.3 to eliminate the vulnerability,” the company noted.
For those who can’t update to the fixed version, the company has released a security patch plugin (that addresses only CVE-2024-23917). Internet-facing servers should be made temporarily inaccessible until the patches have been applied.
“TeamCity Cloud servers have already been patched and we have verified that they weren’t attacked,” the company shared.
JetBrain’s advisory didn’t mention whether the vulnerability is being leveraged to target vulnerable on-premises servers.
JetBrains TeamCity servers under attack
JetBrains TeamCity servers have been a popular target for various state-sponsored hacking groups last year. Those attackers leveraged another authentication bypass vulnerability (CVE-2023-42793) affecting TeamCity On-Premises servers.
Russian state-sponsored hackers have been leveraging the vulnerability since September 2023, and North Korean hackers have been exploiting it since early October, 2023.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/02/07/cve-2024-23917/