Executive brief
JetBrains TeamCity contains an authentication bypass vulnerability (CWE-288) that allows a remote, unauthenticated attacker to perform administrative actions. The flaw exists in versions prior to 2023.11.4 and has been observed being exploited in the wild.
Affected products
- JetBrains TeamCity before 2023.11.4
Timeline
- 2024-03-04: disclosed: Initial CVE publication by JetBrains
- 2024-03-07: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2024-03-07: advisory: NVD publication date