A critical authentication bypass vulnerability impacting a leading continuous integration and continuous deployment build server has been disclosed. The security defect allows unauthenticated remote adversaries to bypass login verification screens and claim full administrative privileges on target build platforms.
The security flaw affects JetBrains TeamCity On-Premises installations. The issue resides within an unverified endpoint handler processing incoming web requests. An unauthenticated attacker can format specialized API calls to bypass authentication controllers, create rogue administrator accounts, or generate administrative access tokens. Once administrative control is secured, the adversary can execute arbitrary code on build agents, modify pipeline scripts, and access source code repositories.
Subverting build automation infrastructure poses a severe software supply chain hazard. Because CI/CD platforms hold signing certificates, deployment keys, and direct connections to cloud production environments, an administrative takeover allows attackers to tamper with software releases, inject backdoors, and pivot into corporate cloud infrastructure.
– Apply current security updates and maintenance hotfixes released by JetBrains across all TeamCity On-Premises servers immediately.
– Restrict web access to TeamCity management portals by placing build servers behind authenticated zero trust access gateways.
– Inspect administrative user account rosters and audit logs for unauthorized user additions or anomalous API key creations.
– Rotate all production deployment credentials, signing certificates, and cloud keys stored within build variables.
Continuous integration pipeline protection requires continuous identity verification to ensure build servers remain completely shielded from unauthenticated access manipulation. #CodeDefence #JetBrains #TeamCity #AuthBypass #RCE #DevSecOps #SupplyChain #AppSec
/
