Critical JetBrains TeamCity vulnerability could be exploited to launch supply chain attacks (CVE-2023-42793)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-42793 | Authentication bypass in JetBrains TeamCity enables unauthenticated RCE JetBrains TeamCity Server, a widely used CI/CD build server, contains an authentication bypass vulnerability (CWE-288) that lets a remote, unauthenticated attacker gain administrative access without valid credentials. By sending crafted requests to the TeamCity server over the network, the attacker bypasses authentication and can then execute arbitrary code on the server via administrative and build features, achieving full remote code execution. An attacker gains control of the build server and, with it, access to source code, build artifacts, stored secrets and credentials, and a foothold for lateral movement or ransomware deployment. Any organization running an affected TeamCity Server is affected, especially instances reachable from the internet. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2023-10-04 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Upgrade TeamCity Server to 2023.05.4 or later per JetBrains' instructions, or apply vendor mitigations or discontinue use if patching is not possible (per the CISA KEV required action). Also take unpatched instances off the public internet, and hunt for signs of compromise such as unauthorized administrator accounts, unexpected changes in audit logs and build configurations, and stored secrets or tokens that may have been stolen, given known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largeTens of thousands of TeamCity Server deployments, of which several thousand are internet-exposed |
Full article365 words · extracted from helpnetsecurity.com · click to collapse
Software development firm JetBrains has fixed a critical vulnerability (CVE-2023-42793) in its TeamCity continuous integration and continuous delivery (CI/CD) solution, which may allow authenticated attackers to achieve remote code execution and gain control of the server.

“As of September 25, 2023, Rapid7 is not aware of in-the-wild exploitation of CVE-2023-42793, and no public exploit code is available,” shared Caitlin Condon, head of vulnerability research at Rapid7.
About CVE-2023-42793
CVE-2023-42793 is an authentication bypass vulnerability that affects versions 2023.05.3 and below of TeamCity On-Premises.
According to Stefan Schiller, a security researcher with Sonar who reported the flaw, attackers don’t have to rely on user interaction to trigger it.
“[The vulnerability] enables attackers not only to steal source code but also stored service secrets and private keys. And it’s even worse: With access to the build process, attackers can inject malicious code, compromising the integrity of software releases and impacting all downstream users,” Shiller added.
Upgrade, patch or block Internet access to the server
CVE-2023-42793 has been fixed in version 2023.05.4 of TeamCity On-Premises.
Customers who are unable to upgrade to it can implement a patch, but should know the patch fixes only that flaw. Users running TeamCity 2018.2 and later won’t have to restart the server to enable the plugin once installed, but those running versions 8.0 to 2018.1 must perform a server restart.
“While we won’t be disclosing technical details at this time, we want to emphasize the importance of prompt action to mitigate this risk. Because this vulnerability does not require a valid account on the target instance and is trivial to exploit, it is likely that this vulnerability will be exploited in the wild,” Schiller commented, and noted that Shodan currently shows over 3,000 on-premises TeamCity servers accessible from the Internet.
In case upgrading or installing the patch can’t be done immediately, users should mitigate the risk of exploitation by making their server temporarily inaccessible.
UPDATE (September 28, 2023, 05:40 a.m. ET):
Rapid7 has published a technical analysis of the vulnerability and has shared possible indicators of compromise.
UPDATE (September 29, 2023, 08:55 a.m. ET):
Greynoise is tracking many IP addresses from which CVE-2023-42793 exploit attempts of are being made.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/09/26/cve-2023-42793/