JetBrains is informing customers of a critical vulnerability in TeamCity On-Premises, continuous integration and development (CI/CD) software.

This problem can be exploited by hackers to cause vulnerable situations.
The vulnerability, also known as CVE-2024-23917, has a CVSS score of 9.8 out of 10, indicating its severity.
Read more: Linux: Critical vulnerability affects most distributions by introducing bootkits
The company says the vulnerability could allow a hacker to gain unauthenticated HTTP(S) access to a TeamCity server and bypass authentication checks, gaining administrative control.
The vulnerability affects all versions of JetBrains TeamCity On-Premises from 2017.1 to 2023.11.2. It has been fixed in version 2023.11.3. An anonymous external security confirmed that he discovered and reported the flaw on January 19, 2024.
Users who are unable to update their servers to version 2023.11.3 can download a security plug-in for the update. This will allow fixes to be applied for the identified issue .
“If your server is accessible over the Internet and it is not possible to immediately take one of the above steps to mitigate the risk, we recommend temporarily making it inaccessible until the necessary actions are completed.” This is JetBrains’ advice.

See also: Many NFT collections at risk due to flaw in open source library
Despite the lack of evidence that the vulnerability has been exploited, it is worth noting that a similar flaw (CVE-2023-42793, CVSS score: 9.8) was exploited last year just days after several threat actors publicly disclosed it. These include ransomware gangs and state-run groups linked to North Korea and Russia.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
