CVE-2024-23917 is a critical authentication bypass vulnerability affecting JetBrains TeamCity versions prior to 2023.11.3, which can lead to remote code execution (RCE). This flaw carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, the vulnerability has high community attention with multiple media articles and a Nuclei template available, indicating a high likelihood of exploitation. Organizations using affected TeamCity versions should update immediately to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2023.11.3CPE match | cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:* | ||
< 2023.11.3CPE matchmatch criteria | cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.