CVE-2023-42793: In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

9.8 CVSS

Description

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

Classification

CVE ID: CVE-2023-42793

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

Affected Products

Vendor: JetBrains

Product: TeamCity

Nuclei Template

http/cves/2023/CVE-2023-42793.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 97.49% (probability of being exploited)

EPSS Percentile: 99.99% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://www.jetbrains.com/privacy-security/issues-fixed/
https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/
http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html
https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793
https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/
https://www.rapid7.com/blog/post/2023/09/25/etr-cve-2023-42793-critical-authentication-bypass-in-jetbrains-teamcity-ci-cd-servers/
https://www.sonarsource.com/blog/teamcity-vulnerability/

Timeline