ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Patched Critical Flaw Exposed JetBrains TeamCity Servers

criticalVulnerability exploited in the wildimportance 60CVE-2024-23917CVE-2023-42793

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-42793
Authentication bypass in JetBrains TeamCity enables unauthenticated RCE

JetBrains TeamCity Server, a widely used CI/CD build server, contains an authentication bypass vulnerability (CWE-288) that lets a remote, unauthenticated attacker gain administrative access without valid credentials. By sending crafted requests to the TeamCity server over the network, the attacker bypasses authentication and can then execute arbitrary code on the server via administrative and build features, achieving full remote code execution. An attacker gains control of the build server and, with it, access to source code, build artifacts, stored secrets and credentials, and a foothold for lateral movement or ransomware deployment. Any organization running an affected TeamCity Server is affected, especially instances reachable from the internet. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2023-10-04 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Upgrade TeamCity Server to 2023.05.4 or later per JetBrains' instructions, or apply vendor mitigations or discontinue use if patching is not possible (per the CISA KEV required action). Also take unpatched instances off the public internet, and hunt for signs of compromise such as unauthorized administrator accounts, unexpected changes in audit logs and build configurations, and stored secrets or tokens that may have been stolen, given known ransomware exploitation.

9.8100% KEV ransomware PoC ×2
  • JetBrains TeamCity (TeamCity Server) On-premises TeamCity Server prior to the fixed release (2023.05.4 per the vendor advisory); the CISA entry lists the affected product without a version range
largeTens of thousands of TeamCity Server deployments, of which several thousand are internet-exposed
CVE-2024-23917
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

NVD description · AI analysis pending
9.854%
  • jetbrains teamcity
Full article374 words · extracted from infosecurity-magazine.com · click to collapse

JetBrains issued a critical security alert on Tuesday for its TeamCity On-Premises software, warning of a vulnerability that could grant attackers administrative control over affected servers. 

Tracked as CVE-2024-23917, the flaw carries a CVSS rating of 9.8. All versions from 2017.1 to 2023.11.2 are at risk. 

“Authentication and authorization have been at the top of the OWASP Top Ten for over two decades. And it’s obvious that attackers are now focusing on exploiting these critical defenses and gaining administrative access,” commented Jeff Williams, co-founder and CTO at Contrast Security.

“In addition to Jetbrains, GoAnywhere MFT recently had a similar issue where they forgot to secure the initial account setup page, enabling unauthenticated attackers to gain administrative access.”

Read more on this vulnerability: Exploit Code Released For Critical Fortra GoAnywhere Bug

While TeamCity Cloud servers are patched, On-Premises users are urged to update to version 2023.11.3 immediately. A security patch plugin is available for older versions. The company emphasized prompt action to safeguard systems against potential exploitation.

“The security patch plugin will only address the vulnerability described above. We always recommend upgrading your server to the latest version to benefit from many other security updates,” reads the blog post.

While there is no evidence that the vulnerability has been abused in the wild, a similar flaw in the same product (CVE-2023-42793) came under active exploitation last year within days of public disclosure.

“TeamCity servers have long been targeted by malicious actors, so the first and most important step for organizations impacted is to patch immediately,” commented Brian Contos, CSO at Sevco Security. “Even when that step has been taken, there is a more insidious threat facing impacted companies.”

A recent study from Sevco showed that 15% of IT assets lack coverage from enterprise patch management solutions, while 31% of IT assets remained outside the purview of enterprise vulnerability management systems.

“It’s hard enough to defend the attack surface you know about, but it becomes impossible when there are vulnerable servers that don’t show up on your IT asset inventory,” Contos added. 

“Once the patching is taken care of, security teams must turn their attention to a longer-term, more sustainable approach to vulnerability management. That begins with an accurate IT asset inventory.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/flaw-exposed-jetbrains-teamcity/