JetBrains is encouraging all users of TeamCity (on-prem) to upgrade to the latest version following the disclosure of a critical vulnerability in the CI/CD tool. Tracked as CVE-2024-23917, the vulnerability has been assigned a provisional 9.8 CVSS score and allows unauthenticated remote attackers to take over vulnerable servers with admin privileges. "All versions from 2017.1 through 2023.11.2 are affected by this issue," Daniel Gallo, solutions engineer at JetBrains, said in an advisory. "The issue has been patched in 2023.11.3. We recommend upgrading as soon as possible." The vulnerability only requires attention for admins of on-prem servers since TeamCity Cloud has already been patched. JetBrains also confirmed that no attacks had been detected against TeamCity Cloud, but made no such assertions about the on-prem product. Patching can be carried out by downloading the latest version, using the automatic update feature within TeamCity itself, or by using the security patch plugin which addresses CVE-2024-23917 only. JetBrains said it's always best to just upgrade the whole server – as users will then receive all the other security fixes that come with it – rather than just patching the single vulnerability. If, for whatever reason, any of the patches or mitigations can't be applied immediately, it's recommended that public-facing TeamCity servers should be made inaccessible until the critical flaw is addressed. The disclosure comes just a few months after it was revealed t...
JetBrains urges swift patching of latest critical TeamCity flaw
The Register
·Connor Jones
·Published Feb 7, 2024
·Updated
Affected Software
23 affected components
JetBrains TeamCity=2017.1
JetBrains TeamCity=2017.2
JetBrains TeamCity=2018.1
JetBrains TeamCity=2018.2
JetBrains TeamCity=2019.1
JetBrains TeamCity=2019.2
JetBrains TeamCity=2020.1
JetBrains TeamCity=2020.2
JetBrains TeamCity=2021.1
JetBrains TeamCity=2021.2
JetBrains TeamCity=2022.1
JetBrains TeamCity=2022.2
JetBrains TeamCity=2023.1
JetBrains TeamCity=2023.2
JetBrains TeamCity=2023.3
JetBrains TeamCity=2023.4
JetBrains TeamCity=2023.5
JetBrains TeamCity=2023.6
JetBrains TeamCity=2023.7
JetBrains TeamCity=2023.8
JetBrains TeamCity=2023.9
JetBrains TeamCity=2023.10
JetBrains TeamCity=2023.11
Frequently Asked Questions
1
What is the primary focus of the article?
The article discusses a critical vulnerability in JetBrains TeamCity that requires immediate patching.
2
What is the identifier for the vulnerability mentioned?
The vulnerability is tracked as CVE-2024-23917.
3
Which versions of TeamCity are impacted by the flaw?
The affected versions include TeamCity from 2017.1 to 2023.11.
4
What action is JetBrains recommending to users of TeamCity?
JetBrains is urging users to upgrade to the latest version to mitigate the risk of the vulnerability.
5
What type of software is TeamCity classified as?
TeamCity is classified as a Continuous Integration and Continuous Deployment (CI/CD) tool.