On 13 December 2023, US, Polish and UK agencies warned that Russia's Foreign Intelligence Service (SVR), also tracked as APT 29 and Midnight Blizzard, had been exploiting CVE-2023-42793 in JetBrains TeamCity since September 2023. TeamCity is the build server developers use to compile, test and release software, so it holds the keys to a company's code. The flaw let attackers bypass authorisation through TeamCity's REST authentication token endpoint and run code on the server. The joint advisory says the agencies identified a few dozen compromised companies in the US, Europe, Asia and Australia and more than a hundred compromised devices. After getting in, the SVR dumped Windows credentials, stole registry hives and planted backdoors. The agencies warned that access to a build server could expose source code and signing certificates and be used for supply chain operations, but said the SVR had not yet used these footholds to reach customer networks. JetBrains had fixed the flaw on 18 September 2023.
Key takeaways
- A joint advisory from CISA, the FBI, NSA, Poland's SKW and CERT Polska and the UK's NCSC says the SVR exploited TeamCity flaw CVE-2023-42793 from September 2023 against unpatched, internet-facing servers.
- The exploit bypassed authorisation through TeamCity's user authentication token endpoint; the attackers then dumped credentials with Mimikatz, exfiltrated the SAM, SECURITY and SYSTEM registry hives and in some cases took saved browser logins.
- The agencies identified a few dozen compromised companies and more than a hundred compromised devices, and say this is not the full set.
- No supply chain attack on customers had been seen: the agencies assessed the SVR was likely still in a preparatory phase. Theft of signing certificates was a stated risk, not a confirmed event.
- The identity lesson: a CI/CD server is a machine identity hub, holding tokens, build secrets and signing material, so an exposed build server is an exposed credential store.
At a glance
| Organisations | A few dozen unnamed companies in the US, Europe, Asia and Australia running on-premises JetBrains TeamCity, including software vendors, hosting firms, IT companies, tools manufacturers and an energy trade association |
|---|---|
| When | Exploitation from September 2023; disclosed in a joint advisory on 13 December 2023 |
| Attacker | Russia's Foreign Intelligence Service (SVR), also known as APT 29, the Dukes, CozyBear and NOBELIUM/Midnight Blizzard, per the joint advisory |
| Entry point | CVE-2023-42793, an authorisation bypass in TeamCity On-Premises exploited through the REST authentication token endpoint |
| Identities abused | TeamCity user authentication tokens; Windows credentials and secrets dumped from servers; Kerberos tickets; saved browser logins |
| Impact | Code execution, credential theft, backdoors and persistence on more than a hundred devices; no confirmed supply chain compromise of customers |
| Category | NHI. Incident class: confirmed NHI breach (CI/CD server authentication bypass exploited in the wild, with credential theft) |
What happened
"Software developers use TeamCity software to manage and automate software compilation, building, testing, and releasing," the joint advisory explains. That is why the agencies treated the exploitation as serious. Compromising a TeamCity server, they wrote, "would provide malicious actors with access to that software developer's source code, signing certificates", along with the ability to subvert how software is compiled and deployed. That is "access a malicious actor could further use to conduct supply chain operations." The advisory recalls that the US government attributed the SolarWinds supply chain operation to the SVR in April 2021.
The flaw itself was found by Sonar on 6 September 2023, according to JetBrains, which says it fixed the issue and gave customers mitigation steps on 18 September 2023, in version 2023.05.4 and a security patch plugin for older versions. TeamCity Cloud was not affected. BleepingComputer reports the flaw is rated 9.8 out of 10 and can be exploited by unauthenticated attackers without user interaction. The advisory describes it as insecure handling of specific paths that allows authorisation to be bypassed. Its appendix lists the endpoint /app/rest/users/id:1/tokens/RPC2 as required for the exploit, and notes that server logs show the user ID of the account whose authentication token was used during the attack.
Once on a server, the SVR escalated privileges and moved through the network. The advisory lists Mimikatz run in memory, exfiltration of the SYSTEM, SAM and SECURITY registry hives to recover credentials, SharpChromium in a few cases to take browser cookies, history and saved logins, and Rubeus to craft Kerberos Ticket Granting Tickets. The actors disabled endpoint protection with a vulnerable driver, hid backdoors through DLL hijacking and used a backdoor called GraphicalProton that talks to OneDrive and Dropbox. The agencies found "a few dozen compromised companies" and are aware of "over a hundred compromised devices." They judged the targeting opportunistic: the victims had nothing in common beyond an unpatched, internet-reachable TeamCity server.
The agencies also assessed that "the SVR has not yet used its accesses to software developers to access customer networks" and "is likely still in the preparatory phase of its operation." JetBrains told customers to check their instances even if they patched promptly, because the first recorded attacks were in September 2023. BleepingComputer notes that ransomware gangs and North Korean groups also exploited the same flaw in 2023, which is why unpatched servers were at risk from more than one actor.
Timeline
| Date | Event |
|---|---|
| 6 September 2023 | Sonar discovers CVE-2023-42793 in TeamCity On-Premises, according to JetBrains. |
| 18 September 2023 | JetBrains fixes the flaw and gives customers mitigation steps (version 2023.05.4 or a security patch plugin). |
| September 2023 | The SVR begins exploiting unpatched, internet-facing TeamCity servers, per the joint advisory. |
| 13 December 2023 | CISA, FBI, NSA, SKW, CERT Polska and NCSC publish joint advisory AA23-347A. |
| 14 December 2023 | JetBrains publishes an update urging customers to patch and to check for compromise. |
How it happened: the identity attack path
- Exposed build server. Victims ran on-premises TeamCity servers reachable from the internet and not yet patched for CVE-2023-42793.
- Authentication token endpoint abused. The exploit bypassed authorisation through TeamCity's REST endpoint for user authentication tokens, giving the attackers code execution on the server.
- Credential harvesting. The SVR ran Mimikatz, exfiltrated the SAM, SECURITY and SYSTEM registry hives and, in a few cases, took saved browser logins and cookies.
- Ticket forgery and persistence. The actors crafted Kerberos tickets with Rubeus, created scheduled tasks and hid backdoors, including GraphicalProton, to keep access.
- Supply chain position. With control of build servers, the SVR sat next to source code, signing certificates and release pipelines, though the agencies saw no use of this against customers.
Impact
- Confirmed: a few dozen companies and more than a hundred devices compromised, with credential dumping, backdoors and persistence, according to the joint advisory.
- Not confirmed: theft of signing certificates, tampering with builds or access to customer networks. The agencies said the SVR had not yet used its developer access against customers.
- Potential: access to source code, signing certificates and compilation and deployment processes, which the advisory says could be used for supply chain operations.
- Wider exposure: BleepingComputer cites Shadowserver tracking almost 800 vulnerable TeamCity servers, and JetBrains saying more than 98% of servers had been patched.
What this means for NHI governance
The NHI angle here is the one the advisory itself draws. A build server is where an organisation's machine identities meet: tokens that let pipelines pull code, secrets that let builds deploy, and certificates that sign what is released. The exploit worked through TeamCity's own authentication token mechanism, and the attackers followed it with large-scale credential theft. Whatever the build server could reach, they could potentially reach.
The same actor used stolen application credentials in the Microsoft Midnight Blizzard breach and a build system compromise in SolarWinds. The lesson is to treat CI/CD servers as tier-zero assets: keep them off the internet, give pipelines short-lived and narrowly scoped credentials, keep signing keys in hardware or a managed signing service rather than on the build host, and rotate everything the server held after a compromise. Our CI/CD Pipeline Identity Security Guide and Machine Identity, PKI and Certificate Lifecycle Guide cover these controls.
Recommendations
- Patch build servers first and keep them off the internet. TeamCity was fixed in September 2023; the SVR exploited servers left exposed after that. Put CI/CD consoles behind a VPN or zero trust access. See our CI/CD Pipeline Identity Security Guide.
- Investigate even if you patched. JetBrains advised checking instances patched after the first attacks, using the indicators in the joint advisory.
- Rotate every secret a compromised build server held. Treat pipeline tokens, deployment keys, service account passwords and cached credentials on the host as stolen. See the Leaked Credential Response Playbook.
- Move signing keys off build hosts. Use hardware security modules or a managed signing service, so a server compromise does not give away the ability to sign releases. See our Machine Identity, PKI and Certificate Lifecycle Guide.
- Scope and shorten pipeline credentials. Replace long-lived tokens with short-lived, workload-bound credentials so stolen material expires quickly. See our Cloud Workload Identity Guide.
- Watch build servers for credential dumping. Alert on Mimikatz-style activity, registry hive exports and new scheduled tasks on CI/CD hosts. See our ITDR Guide.
Frequently asked questions
What is CVE-2023-42793?
CVE-2023-42793 is a critical authorisation bypass in JetBrains TeamCity On-Premises, found by Sonar and fixed by JetBrains on 18 September 2023. It lets an unauthenticated attacker abuse TeamCity's REST authentication token endpoint and run code on the server. TeamCity Cloud was not affected.
Did the SVR use TeamCity access for a supply chain attack?
Not as far as the agencies could see. The December 2023 joint advisory said the SVR had not yet used its access to software developers to reach customer networks and was likely still in a preparatory phase, while warning that the access could be used for supply chain operations.
Why are CI/CD servers valuable to attackers?
Build servers hold source code, pipeline tokens, deployment secrets and often signing certificates, and they produce the software customers install. Control of one can mean access to many downstream systems, which is why the advisory compared the risk to the SolarWinds operation.
Related NHI Mgmt Group resources
SolarWinds Supply Chain Compromise · Microsoft Midnight Blizzard Breach 2024 · CircleCI Breach 2023 · CI/CD Pipeline Identity Security Guide · Machine Identity, PKI and Certificate Lifecycle Guide
How NHI Mgmt Group can help
Build servers concentrate tokens, secrets and signing keys in one place. We help teams map the machine identities their pipelines hold, cut them down to short-lived, scoped credentials and plan what to rotate when a build server is compromised. See our NHI and AI agent security training.
References
- CISA, FBI, NSA, SKW, CERT Polska and NCSC: Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally (AA23-347A) (13 December 2023)
- BleepingComputer: CISA: Russian hackers target TeamCity servers since September (13 December 2023)
- JetBrains: CVE-2023-42793 Vulnerability in TeamCity: December 14, 2023 Update (14 December 2023)