CVE-2023-42793
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.98% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-10-04, used in ransomware campaigns
- Nuclei
- critical · CWE-288
- Published
- 2023-09-19
- Updated
- 2025-10-21
Proof-of-concept exploits (20)
- http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Cod…
- B4l3rI0n/CVE-2023-4279311★ · 2024-04-24
- FlojBoj/CVE-2023-427930★ · 2024-08-25
- H454NSec/CVE-2023-4279345★ · 2024-05-22
- HusenjanDev/CVE-2023-427931★ · 2024-07-05
- StanleyJobsonAU/GhostTown0★ · 2024-01-15
- SwiftSecur/teamcity-exploit-cve-2023-427931★ · 2024-11-06
- YN1337/JetBrains-TeamCity-0★ · 2024-06-04
- Zenmovie/CVE-2023-427939★ · 2023-10-11
- Zyad-Elsayed/CVE-2023-4279311★ · 2024-04-24
- becrevex/CVE-2023-427930★ · 2025-03-29
- brun0ne/teamcity-enumeration0★ · 2024-04-23
- hotplugin0x01/CVE-2023-427932★ · 2024-05-06
- jakehomb/cve-2023-427930★ · 2025-04-14
- johnossawy/CVE-2023-42793_POC0★ · 2024-01-08
- junnythemarksman/CVE-2023-427931★ · 2024-05-27
- whoamins/CVE-2023-427930★ · 2023-10-23
- DDestinys/CVE-2023-42793
- cxdxnt/CVE-2023-42793
- chengbochuan3/CVE-CICD-Security