logo

Patch Now: Critical TeamCity Bug Allows for Server Takeovers

ID: ad45526f-edaf-510b-bd8d-b05531b2cc0d

STIX ID: report--ad45526f-edaf-510b-bd8d-b05531b2cc0d

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-02-07

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

JetBrains released fixes for a critical authentication-bypass in TeamCity On-Premises (CVE-2024-23917) affecting versions 2017.1 through 2023.11.2 that could allow unauthenticated remote attackers to gain administrative control; the vendor published an updated release (2023.11.3) and a security-plugin mitigation and urges immediate patching or removal of public access, noting the elevated risk given prior exploitation of TeamCity vulnerabilities by state-sponsored actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.