None
EN
Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands
['Techrepublic Staff']
TechRepublic
JetBrains has patched a critical TeamCity vulnerability that could allow unauthenticated attackers to run operating system commands on exposed, self-hosted servers.
JetBrains releases emergency TeamCity fixesIn a security advisory, JetBrains said attackers could exploit the TeamCity agent polling protocol without authenticating.
Successful exploitation could bypass access controls and execute commands with the privileges assigned to the TeamCity server process.
Organizations unable to complete a full upgrade immediately can install JetBrains’ security patch plugin on TeamCity 2017.1 or later.
Earlier TeamCity vulnerabilities also show why patching should not wait for confirmed attacks.