Oddbean new post about | logout
 JetBrains has released a security update for TeamCity on-premise CI/CD servers to fix an authentication bypass vulnerability that could have allowed attackers to run malicious code on customer systems.

https://blog.jetbrains.com/teamcity/2023/09/critical-security-issue-affecting-teamcity-on-premises-update-to-2023-05-4-now/ 
 @14abadff FYI Rapid7 appears to have posted a Proof of Concept for #CVE202342793 
https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793/rapid7-analysis
They also rate attacker value for CVE-2023-42793 as very high, and the exploitability for this vulnerability very high: https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793