CVE-2023-42793
CRITICAL KEV RANSOMWARE NUCLEIJetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
Title source: llmExploitation Summary
CVE-2023-42793 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 4, 2023, with confirmed use in ransomware campaigns.
EIP tracks 19 public exploits from researchers including ByteHunter, H454NSec, B4l3rI0n, including a Metasploit module exploits/multi/http/jetbrains_teamcity_rce_cve_2023_42793.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages CVE-2023-42793 to create an admin account in JetBrains TeamCity by abusing token generation and user creation endpoints. It automates the process of retrieving or deleting an existing token and then creating a new admin user with SYSTEM_ADMIN privileges.
Description
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Exploits (19)
This exploit leverages CVE-2023-42793 to create an admin account in JetBrains TeamCity by abusing token generation and user creation endpoints. It automates the process of retrieving or deleting an existing token and then creating a new admin user with SYSTEM_ADMIN privileges.
This repository contains a functional Python exploit for CVE-2023-42793, which targets JetBrains TeamCity. The exploit creates a new administrative user by manipulating user tokens via REST API calls.
This repository contains functional exploit code for CVE-2023-42793, which allows unauthenticated admin account creation in TeamCity, leading to RCE. The exploit consists of two Python scripts: one for creating an admin account and another for executing commands via the TeamCity API.
The repository contains functional exploit scripts for CVE-2023-42793, demonstrating authentication bypass and remote code execution (RCE) in JetBrains TeamCity. The scripts leverage token generation and API endpoints to create an admin user and execute arbitrary commands.
This repository contains a functional exploit for CVE-2023-42793, an authentication bypass vulnerability in JetBrains TeamCity leading to RCE. The exploit leverages token manipulation and file editing to enable debug processes, then executes a reverse shell via crafted API requests.
This Nuclei template exploits CVE-2023-42793, an authentication bypass leading to RCE in JetBrains TeamCity. It chains token manipulation, file modification, and process execution to achieve remote code execution.
This repository contains functional exploit scripts for CVE-2023-42793, a JetBrains TeamCity authentication bypass and RCE vulnerability. The scripts automate the exploitation process by enabling debug mode, generating a bearer token, and executing arbitrary commands via the vulnerable endpoint.
This repository contains a functional exploit for CVE-2023-42793, which targets TeamCity servers. The exploit enables debug mode and sends a reverse shell payload via a crafted URL, achieving remote code execution (RCE).
This repository contains a functional exploit for CVE-2023-42793, which allows an attacker to create a new administrative user in JetBrains TeamCity. The exploit leverages a token deletion and subsequent user creation via API calls.
This repository contains a functional exploit for CVE-2023-42793, an authentication bypass vulnerability in JetBrains TeamCity. The script automates the process of creating a token, generating an admin user, and verifying successful login.
This repository contains functional exploit code for CVE-2023-42793, demonstrating remote code execution (RCE) and user creation with administrator privileges in TeamCity. The exploit leverages token manipulation and API endpoints to achieve RCE and privilege escalation.
This repository contains a functional exploit for CVE-2023-42793, targeting JetBrains TeamCity. The exploit authenticates via RPC token, enables debug mode, and executes arbitrary commands, demonstrating remote code execution (RCE).
This Go-based exploit demonstrates an authentication bypass vulnerability in JetBrains TeamCity (CVE-2023-42793) by retrieving a token from an admin user and creating a new admin user. It leverages improper access control to escalate privileges.
The repository provides an Nmap NSE script to detect CVE-2023-42793, an authentication bypass vulnerability in JetBrains TeamCity. The script checks for the vulnerability by attempting to create an admin user via the exposed endpoint.
The repository contains two functional exploit scripts for CVE-2023-42793, a TeamCity vulnerability. The first script (`exploit.py`) creates an admin account, while the second (`rce.py`) achieves remote code execution by enabling debug processes and executing arbitrary commands.
This PoC exploits CVE-2023-42793 in TeamCity by generating an admin token, modifying internal configurations to enable debug processes, and executing a reverse shell via a crafted request to the debug endpoint.
This script automates the exploitation of CVE-2023-42793 by deleting a user token, creating a new token, and then creating a new user with administrative privileges in TeamCity. It demonstrates an authentication bypass vulnerability.
This PoC exploits CVE-2023-42793 in JetBrains TeamCity by creating a new admin user via an authentication bypass. It retrieves an admin session token, deletes it if it exists, and then creates a new admin user with SYSTEM_ADMIN privileges.
This Metasploit module exploits CVE-2023-42793, an authentication bypass vulnerability in JetBrains TeamCity, to achieve unauthenticated remote code execution by modifying internal properties and executing arbitrary commands.
Nuclei Templates (1)
title:TeamCity || http.title:teamcity || http.component:"teamcity"
title=TeamCity || title=teamcity
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H