• News/
  • https://www.bleepingcomputer.com/news/security/jetbrains-warns-of-new-teamcity-auth-bypass-vulnerability/

JetBrains warns of new TeamCity auth bypass vulnerability

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 6, 2024
·
Updated

JetBrains urged customers today to patch their TeamCity On-Premises servers against a critical authentication bypass vulnerability that can let attackers take over vulnerable instances with admin privileges. Tracked as CVE-2024-23917, this critical severity flaw impacts all versions of TeamCity On-Premises from 2017.1 through 2023.11.2 and can be exploited in remote code execution (RCE) attacks that don't require user interaction. "We strongly advise all TeamCity On-Premises users to update their servers to 2023.11.3 to eliminate the vulnerability," JetBrains said. "If your server is publicly accessible over the internet and you are unable to take one of the above mitigation steps immediately, we recommend temporarily making it inaccessible until mitigation actions have been completed." Customers who cannot immediately upgrade can also use a security patch plugin to secure servers running TeamCity 2018.2+ and TeamCity 2017.1, 2017.2, and 2018.1. While the company says that all TeamCity Cloud servers have been patched and there is no evidence they've been attacked, it has yet to reveal if CVE-2024-23917 has been targeted in the wild to hijack Internet-exposed TeamCity On-Premises servers. Shadowserver is tracking more than 2,000 TeamCity servers exposed online, although there is no way to know how many have already been patched. ​A similar authentication bypass flaw tracked as CVE-2023-42793 was exploited by the APT29 hacking group linked to Russia's Foreign Intelligence Serv...

Read full article

Affected Software

22 affected components
JetBrains TeamCity On-Premises=2017.1
JetBrains TeamCity On-Premises=2017.2
JetBrains TeamCity On-Premises=2018.1
JetBrains TeamCity On-Premises=2018.2
JetBrains TeamCity On-Premises=2019.1
JetBrains TeamCity On-Premises=2019.2
JetBrains TeamCity On-Premises=2020.1
JetBrains TeamCity On-Premises=2020.2
JetBrains TeamCity On-Premises=2021.1
JetBrains TeamCity On-Premises=2022.1
JetBrains TeamCity On-Premises=2022.2
JetBrains TeamCity On-Premises=2023.1
JetBrains TeamCity On-Premises=2023.2
JetBrains TeamCity On-Premises=2023.3
JetBrains TeamCity On-Premises=2023.4
JetBrains TeamCity On-Premises=2023.5
JetBrains TeamCity On-Premises=2023.6
JetBrains TeamCity On-Premises=2023.7
JetBrains TeamCity On-Premises=2023.8
JetBrains TeamCity On-Premises=2023.9
JetBrains TeamCity On-Premises=2023.10
JetBrains TeamCity On-Premises=2023.11

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises.

2

What is the severity level of the identified vulnerability?

The vulnerability is classified as critical severity.

3

What is the identifier assigned to the vulnerability?

The vulnerability is tracked as CVE-2024-23917.

4

What can attackers do if they exploit this vulnerability?

Attackers can take over vulnerable TeamCity instances with admin privileges.

5

What action has JetBrains recommended for customers?

JetBrains urged customers to patch their TeamCity On-Premises servers immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203