CVE-2023-42793

CRITICAL KEV RANSOMWARE NUCLEI

Jetbrains Teamcity < 2023.05.4 - Missing Authentication

Title source: rule

Description

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

Exploits (19)

exploitdb WORKING POC
by ByteHunter · pythonremotejava
https://www.exploit-db.com/exploits/51884
nomisec WORKING POC 45 stars
by H454NSec · remote
https://github.com/H454NSec/CVE-2023-42793
nomisec WORKING POC 10 stars
by B4l3rI0n · remote
https://github.com/B4l3rI0n/CVE-2023-42793
nomisec WORKING POC 8 stars
by Zenmovie · remote
https://github.com/Zenmovie/CVE-2023-42793
nomisec WORKING POC 2 stars
by hotplugin0x01 · remote
https://github.com/hotplugin0x01/CVE-2023-42793
nomisec WORKING POC 1 stars
by syaifulandy · remote
https://github.com/syaifulandy/Nuclei-Template-CVE-2023-42793.yaml
nomisec WORKING POC 1 stars
by SwiftSecur · remote
https://github.com/SwiftSecur/teamcity-exploit-cve-2023-42793
nomisec WORKING POC 1 stars
by HusenjanDev · remote
https://github.com/HusenjanDev/CVE-2023-42793
nomisec WORKING POC 1 stars
by junnythemarksman · remote
https://github.com/junnythemarksman/CVE-2023-42793
nomisec WORKING POC
by DDestinys · remote
https://github.com/DDestinys/CVE-2023-42793
nomisec WORKING POC
by cxdxnt · remote
https://github.com/cxdxnt/CVE-2023-42793
nomisec WORKING POC
by syorik · remote
https://github.com/syorik/CVE-2023-42793
nomisec WORKING POC
by jakehomb · remote
https://github.com/jakehomb/cve-2023-42793
nomisec SCANNER
by becrevex · remote
https://github.com/becrevex/CVE-2023-42793
nomisec WORKING POC
by FlojBoj · remote
https://github.com/FlojBoj/CVE-2023-42793
nomisec WORKING POC
by StanleyJobsonAU · remote
https://github.com/StanleyJobsonAU/GhostTown
nomisec WORKING POC
by johnossawy · poc
https://github.com/johnossawy/CVE-2023-42793_POC
nomisec WORKING POC
by whoamins · poc
https://github.com/whoamins/CVE-2023-42793
metasploit WORKING POC EXCELLENT
by sfewer-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2023_42793.rb

Nuclei Templates (1)

JetBrains TeamCity < 2023.05.4 - Remote Code Execution
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan: title:TeamCity || http.title:teamcity || http.component:"teamcity"
FOFA: title=TeamCity || title=teamcity

Scores

CVSS v3 9.8
EPSS 0.9291
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-10-04
VulnCheck KEV 2023-10-01
InTheWild.io 2023-10-04
ENISA EUVD EUVD-2023-47222
Ransomware Use Confirmed
CWE
CWE-306 CWE-288
Status published
Products (1)
jetbrains/teamcity < 2023.05.4
Published Sep 19, 2023
KEV Added Oct 04, 2023
Tracked Since Feb 18, 2026