In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
Published: 2024-03-06
Two vulnerabilities with publicly available exploit code in JetBrains TeamCity on-premises software could result in attackers bypassing authentication and achieving code execution.
https://securelist.com/vulnerability-report-q1-2024/112554/
https://thehackernews.com/2024/03/bianlian-threat-actors-exploiting.html
https://www.guidepointsecurity.com/blog/bianlian-gos-for-powershell-after-teamcity-exploitation/
https://www.theregister.com/2024/03/07/teamcity_exploits_lead_to_ransomware/