Executive brief
An authentication bypass vulnerability in JetBrains TeamCity allows unauthenticated attackers to perform remote code execution (RCE) on the TeamCity Server. The flaw stems from missing authentication for critical functions or an alternate path/channel bypass.
Affected products
- JetBrains TeamCity before 2023.05.4
Timeline
- 2023-09-25: disclosed: Public blog posts regarding the vulnerability published by Rapid7 and JetBrains.
- 2023-10-04: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
- 2023-10-04: advisory: NVD publication date.
- 2023-10-04: exploited: Reported as exploited in the wild.