Collected research
Source Code at Risk: Critical Code Vulnerability in CI/CD Platform TeamCity
TeamCity excluded any path matching the wildcard /**/RPC2 from all global request interceptors, which is where its authorization check lives, so any URL ending in /RPC2 was served unauthenticated. An undocumented REST route lets the token name be supplied as a path segment, so an unauthenticated POST to /app/rest/users/id:1/tokens/RPC2 mints an admin token (CVE-2023-42793), giving full server takeover, source code and secret theft, and the ability to poison build artifacts.
Record
- Researcher
- Stefan Schiller
- Published by
- Sonar
- Date
- Topic
- Supply
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Stefan Schiller, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .