Skip to content
COOEY

EXPOSURES › CVE-2023-42793

CVE-2023-42793

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-42793 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatchedauth-bypass

JetBrains TeamCity suffered an authentication bypass leading to remote code execution, actively exploited by ransomware actors.

The authentication bypass in JetBrains TeamCity allowed attackers to execute arbitrary code on the server without valid credentials. DIB organizations must ensure their CI/CD platforms are patched and monitored, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns. Failure to patch such critical flaws exposes build pipelines to compromise and potential data exfiltration.

Shame score — A critical authentication bypass enabling remote code execution was actively exploited by ransomware actors, indicating severe negligence in patch management and threat monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.