EXPOSURES › CVE-2023-42793
CVE-2023-42793
CRITICAL ⌖ ON CISA KEV · EXPLOITEDJetBrains TeamCity suffered an authentication bypass leading to remote code execution, actively exploited by ransomware actors.
The authentication bypass in JetBrains TeamCity allowed attackers to execute arbitrary code on the server without valid credentials. DIB organizations must ensure their CI/CD platforms are patched and monitored, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns. Failure to patch such critical flaws exposes build pipelines to compromise and potential data exfiltration.
Shame score — A critical authentication bypass enabling remote code execution was actively exploited by ransomware actors, indicating severe negligence in patch management and threat monitoring.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.