2024-05-25 21:48:12 +02:00
|
|
|
### [CVE-2023-42793](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42793)
|
|
|
|

|
|
|
|

|
|
|
|

|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
#### Reference
|
|
|
|
- http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html
|
|
|
|
- https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793
|
|
|
|
- https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/
|
|
|
|
|
|
|
|
#### Github
|
|
|
|
- https://github.com/20142995/sectool
|
|
|
|
- https://github.com/AdamCrosser/awesome-vuln-writeups
|
|
|
|
- https://github.com/H454NSec/CVE-2023-42793
|
|
|
|
- https://github.com/LeHeron/TC_test
|
|
|
|
- https://github.com/Ostorlab/KEV
|
|
|
|
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
|
2024-05-28 08:49:17 +00:00
|
|
|
- https://github.com/SrcVme50/Runner
|
|
|
|
- https://github.com/St0rm-85/CVE-2023-42793
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/StanleyJobsonAU/GhostTown
|
2024-05-28 08:49:17 +00:00
|
|
|
- https://github.com/Threekiii/Awesome-POC
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/Threekiii/Vulhub-Reproduce
|
|
|
|
- https://github.com/UNC1739/awesome-vulnerability-research
|
|
|
|
- https://github.com/WhiteOwl-Pub/PoC-JetBrains-TeamCity-CVE-2023-42793
|
|
|
|
- https://github.com/Y4tacker/JavaSec
|
2024-06-10 07:22:43 +00:00
|
|
|
- https://github.com/YN1337/JetBrains-TeamCity-
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/Zenmovie/CVE-2023-42793
|
2024-05-28 08:49:17 +00:00
|
|
|
- https://github.com/Zyad-Elsayed/CVE-2023-42793
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/aleksey-vi/presentation-report
|
2024-05-28 08:49:17 +00:00
|
|
|
- https://github.com/brun0ne/teamcity-enumeration
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/getdrive/PoC
|
2024-05-28 08:49:17 +00:00
|
|
|
- https://github.com/hotplugin0x01/CVE-2023-42793
|
2024-08-07 19:02:05 +00:00
|
|
|
- https://github.com/ibaiw/2024Hvv
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/johnossawy/CVE-2023-42793_POC
|
2024-06-10 07:22:43 +00:00
|
|
|
- https://github.com/junnythemarksman/CVE-2023-42793
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/netlas-io/netlas-dorks
|
2024-08-05 18:41:32 +00:00
|
|
|
- https://github.com/nitish778191/fitness_app
|
2024-05-25 21:48:12 +02:00
|
|
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
|
|
|
- https://github.com/whitfieldsdad/cisa_kev
|
|
|
|
|