PT-2023-5743 · Jetbrains · Jetbrains Teamcity+1

·

CVE-2023-42793

·

Published

2023-09-19

·

Updated

2026-09-06

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2023.05.4
Description An authentication bypass exists in the server API due to insufficient access control, allowing an unauthenticated remote attacker to gain administrative access to the console and guest portal. This can lead to remote code execution (RCE) on the TeamCity Server and its agents, enabling the theft of source code, service secrets, and private keys, or the injection of malicious code into software builds to facilitate supply chain attacks. The issue is exploited by sending a request matching the pattern /**/RPC2 to the undocumented endpoint /app/rest/users/id:1/tokens/RPC2 to retrieve the authentication token of the default administrator account. Real-world exploitation has been observed on a large scale by state-sponsored actors, including APT 29 (CozyBear/NOBELIUM/Midnight Blizzard), Lazarus Group, Diamond Sleet, and Onyx Sleet. Approximately 1,258 potentially affected instances were identified via ZoomEye, with over 3,000 servers reported as directly connected to the internet via Shodan.
Recommendations Update JetBrains TeamCity to version 2023.05.4. As a temporary mitigation if updating is not possible, install the security patch plugin provided by JetBrains for versions 8.0 and above.

Exploit

Fix

DoS

RCE

Authentication Bypass Using an Alternate Path or Channel

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06415
CVE-2023-42793

Affected Products

Jetbrains Teamcity
Teamcity