logo

JetBrains urges swift patching of latest critical TeamCity flaw

ID: 226a390d-35a3-5790-ad74-01c00f33ed80

STIX ID: report--226a390d-35a3-5790-ad74-01c00f33ed80

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-02-07

Date Updated: 2026-04-26

Author: Connor Jones

...
...

JetBrains disclosed a critical on-premises TeamCity vulnerability (CVE-2024-23917, provisional CVSS 9.8) affecting versions 2017.1 through 2023.11.2 that can allow unauthenticated remote attackers to gain admin privileges; the issue was patched in 2023.11.3 and administrators are urged to upgrade, apply the security patch plugin, or take public-facing servers offline until remediated. The advisory notes TeamCity Cloud was already patched and references past state-sponsored targeting of TeamCity (CVE-2023-42793) where foreign actors exploited similar flaws to move laterally and deploy backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.