What is the Attack?
Multiple cyberthreat actors seen exploiting the authentication bypass flaw in JetBrains TeamCity that could lead to remote code execution. If compromised, access to a TeamCity server would provide malicious actors with access to the software developer’s source code, signing certificates, and the ability to manipulate software compilation and deployment processes. The malicious actors could further use to conduct supply chain operations.
What is the Vendor Solution?
JetBrains released patch on September 18, 2023 to fix the affected TeamCity software on version 2023.05.4, which can be found here: https://www.jetbrains.com/teamcity/download/other.html.
What FortiGuard Coverage is available?
FortiGuard Labs has an IPS signature “JetBrains.TeamCity.CVE-2023-42793.Authentication.Bypass” (with default action is set to “block”) in place and has released Antivirus signatures for the known and related malware to the campaigns targeting the vulnerability (CVE-2023-42793).
More Stories
APPLE-SA-03-31-2025-8 macOS Sonoma 14.7.5
Posted by Apple Product Security via Fulldisclosure on Apr 02 APPLE-SA-03-31-2025-8 macOS Sonoma 14.7.5 macOS Sonoma 14.7.5 addresses the following...
APPLE-SA-03-31-2025-7 macOS Sequoia 15.4
Posted by Apple Product Security via Fulldisclosure on Apr 02 APPLE-SA-03-31-2025-7 macOS Sequoia 15.4 macOS Sequoia 15.4 addresses the following...
APPLE-SA-03-31-2025-6 iOS 15.8.4 and iPadOS 15.8.4
Posted by Apple Product Security via Fulldisclosure on Apr 02 APPLE-SA-03-31-2025-6 iOS 15.8.4 and iPadOS 15.8.4 iOS 15.8.4 and iPadOS...
APPLE-SA-03-31-2025-5 iOS 16.7.11 and iPadOS 16.7.11
Posted by Apple Product Security via Fulldisclosure on Apr 02 APPLE-SA-03-31-2025-5 iOS 16.7.11 and iPadOS 16.7.11 iOS 16.7.11 and iPadOS...
APPLE-SA-03-31-2025-4 iPadOS 17.7.6
Posted by Apple Product Security via Fulldisclosure on Apr 02 APPLE-SA-03-31-2025-4 iPadOS 17.7.6 iPadOS 17.7.6 addresses the following issues. Information...
APPLE-SA-03-31-2025-3 iOS 18.4 and iPadOS 18.4
Posted by Apple Product Security via Fulldisclosure on Apr 02 APPLE-SA-03-31-2025-3 iOS 18.4 and iPadOS 18.4 iOS 18.4 and iPadOS...