Description: | | JetBrains TeamCity is a set of distributed build management and continuous integration tools from the Czech company JetBrains. The tool provides features such as continuous unit testing, code quality analysis, and build problem analysis reports. Versions prior to JetBrains TeamCity 2023.11.4 have an authentication bypass vulnerability that allows a remote attacker to construct a malicious URL to bypass authentication checks, allowing direct access to the endpoint that requires authentication. A remote attacker could exploit this vulnerability to cause an RCE, create an administrator account, and take full control of a vulnerable TeamCity server, and could further exploit it to cause a supply chain attack. |