Jessica Wight’s Post

View profile for Jessica Wight, graphic

Account Executive @ Recorded Future | Threat Intelligence Solutions

On September 20, 2023, JetBrains disclosed CVE-2023-42793, a critical authentication bypass vulnerability in on-prem instances of their TeamCity CI/CD server. Successful exploitation allows an unauthenticated attacker (with HTTP[S] access to a TeamCity server) to gain administrative control of the server via RCE attack — making this vulnerability a potential supply chain attack vector. 🛡 Find additional information, mitigation guidance and more in our blog: https://r-7.co/455spt5

Critical Authentication Bypass in JetBrains TeamCity CI/CD Servers | Rapid7 Blog

Critical Authentication Bypass in JetBrains TeamCity CI/CD Servers | Rapid7 Blog

rapid7.com

To view or add a comment, sign in

Explore topics