The vulnerability carries a CVSS rating of 9.eight out of 10 because it requires no authentication or person interplay, making internet-exposed TeamCity servers significantly engaging targets. Classified beneath CWE-502 (deserialization of unstructured knowledge), the flaw can be utilized to ship specifically crafted knowledge by the affected agent polling protocol to set off distant code execution (RCE).
“Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines,” the corporate added.
The challenge was privately reported on July 10 by safety researcher Antoni Tremblay by JetBrains’ coordinated disclosure course of.






