CVE-2023-42793: JetBrains TeamCity Authentication Bypass Vulnerability
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Other sources
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2023.05.4 - Compensating control
Discontinue use of the product (JetBrains TeamCity) if vendor mitigations are unavailable, as stated in the vendor remedy text.
Event History
Frequently Asked Questions
What is the vulnerability ID CVE-2023-42793?
The vulnerability ID CVE-2023-42793 refers to an authentication bypass vulnerability in JetBrains TeamCity before version 2023.05.4.
What is the severity of CVE-2023-42793?
The severity of CVE-2023-42793 is critical, with a severity value of 9.8.
How does CVE-2023-42793 impact JetBrains TeamCity?
CVE-2023-42793 allows for authentication bypass, leading to remote code execution (RCE) on the TeamCity Server.
What version of JetBrains TeamCity is affected by CVE-2023-42793?
CVE-2023-42793 affects all versions of JetBrains TeamCity before version 2023.05.4.
How can I fix the vulnerability CVE-2023-42793?
To fix CVE-2023-42793, update JetBrains TeamCity to version 2023.05.4 or later.