In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Link | Tags |
---|---|
https://www.jetbrains.com/privacy-security/issues-fixed/ | vendor advisory |
https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive | third party advisory press/media coverage |