Sept. 29, 2023, 6:08 p.m. | Alan David Foster

Rapid7 Blog blog.rapid7.com

TeamCity authentication bypass and remote code execution


This week’s Metasploit release includes a new module for a critical authentication bypass in JetBrains TeamCity CI/CD Server. All versions of TeamCity prior to version 2023.05.4 are vulnerable to this issue. The vulnerability was originally discovered by SonarSource, and

authentication authentication bypass bypass code code execution critical issue jetbrains jetbrains teamcity metasploit metasploit weekly wrapup release remote code remote code execution server sonarsource teamcity version vulnerability vulnerable week weekly wrap-up

Sr Security Engineer - Colombia

@ Nubank | Colombia, Bogota

Security Engineer, Investigations - i3

@ Meta | Menlo Park, CA | Washington, DC | Remote, US

Cyber Security Engineer

@ ASSYSTEM | Bridgwater, United Kingdom

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States