Executive brief
JetBrains TeamCity, a popular platform for automating software builds and deployments, contains a security vulnerability that allows unauthorized users to perform administrative actions. An attacker could exploit this to bypass security controls and potentially interfere with the software development pipeline. This flaw has been reported as being actively exploited in the wild, posing a significant risk to organizational software integrity and operational continuity.
Technical details
A relative path traversal vulnerability (CWE-23/CWE-22) exists in JetBrains TeamCity versions prior to 2023.11.4. The flaw allows a remote, unauthenticated attacker to bypass certain security constraints by manipulating file paths in web requests. Successful exploitation enables the attacker to perform a limited set of administrative actions on the server. This vulnerability is being actively exploited in the wild, often in conjunction with other flaws to establish persistent access or create rogue accounts. Users should update to version 2023.11.4 or later immediately.
Affected products
- JetBrains TeamCity Before 2023.11.4
Timeline
- 2024-03-04: disclosed: Initial NVD publication
- 2024-03-04: advisory: Vendor advisory released by JetBrains
- 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog