logo

JetBrains warns of new TeamCity auth bypass vulnerability

ID: 2ed29f34-6231-5c38-95d6-2392807c061c

STIX ID: report--2ed29f34-6231-5c38-95d6-2392807c061c

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-02-06

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

JetBrains disclosed a critical authentication bypass in TeamCity On-Premises (CVE-2024-23917) affecting versions 2017.1 through 2023.11.2 that can enable unauthenticated remote code execution; users are urged to upgrade to 2023.11.3 or apply vendor patches, and JetBrains reports cloud servers have been patched with no evidence yet of in-the-wild exploitation, though a similar prior vulnerability was exploited by APT29, North Korean groups, and ransomware actors and Shadowserver reports thousands of TeamCity instances exposed online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.