VDB
GSD-2023-42793
GSD-2023-42793
PUBLISHED
CVSS 9.800000190734863 CRITICAL
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Risk Scores
CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| JetBrains | TeamCity | 0 |
Timeline
- Sep 19, 2023 CVE Published
- Sep 27, 2023 PoC Published
- Sep 28, 2023 PoC Published
- Oct 4, 2023 PoC Published
- Dec 5, 2023 PoC Published
- Dec 14, 2023 PoC Published
- Mar 1, 2024 PoC Published
- Apr 5, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Oct 14, 2024 PoC Published
- Nov 4, 2024 PoC Published
- Nov 5, 2024 PoC Published
References
- https://www.jetbrains.com/privacy-security/issues-fixed/ url
- https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/ url
- http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html url
- https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793 url
- https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/ url
- https://www.rapid7.com/blog/post/2023/09/25/etr-cve-2023-42793-critical-authentication-bypass-in-jetbrains-teamcity-ci-cd-servers/ url
- https://www.sonarsource.com/blog/teamcity-vulnerability/ url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-42793 url