[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"vulnerability-3":48,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":80,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":87,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":93},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":41,"text":42,"link":43,"external":44,"targets":45,"cta":47,"variant":13,"campaign_id":41},"Office Hours #13 - Reducing tool sprawl","office-hours-13","[Live Office Hours, Wed Oct 14] How to consolidate your security testing stack without the lock-in","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_m_Won6d_SzOQ-gYhCdXU_A",true,[46],"\u002F","Save your spot",{"id":49,"detectable_with":50,"vuln_details":56,"vuln_id":77,"name":78,"published":79,"updated":79},3,{"tool":51,"engine":54},{"id":52,"name":53},1,"Network Scanner",{"id":52,"name":55},"Sniper",{"id":49,"codename":57,"description":58,"severity":59,"risk_description":60,"public_description":61,"public_recommendation":62,"recommendation":63,"references":64,"cvssv3":66,"epss_score":67,"epss_percentile":68,"cve":69,"in_cisa_catalog":44,"date":71,"software_type":72,"vendor":73,"product":74,"ptt_exploit_capabilities":75},null,"We found that the target server is vulnerable to CVE-2023-42793, a Remote Code Execution vulnerability, affecting JetBrains TeamCity. The root cause of this vulnerability is the existence of an alternate access path that does not have authentication checks. More exactly, an attacker can access the \u003Ccode>\u002Fapp\u002Frest\u002Fusers\u002Fid:1\u002Ftokens\u002FRPC2\u003C\u002Fcode> path, which requires no authentication, to obtain an authentication token, which can be further used to have unrestricted access to the API exposed by TeamCity. Afterwards, using this token an attacker can enable the possiblity to remotely execute code on the target.\nWe have detected this by obtaining an authentication token, and then enabling the \u003Ccode>rest.debug.processes.enable\u003C\u002Fcode> option. Afterwards we were able to execute the \u003Ccode>echo\u003C\u002Fcode> command on the target.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the TeamCity server in order to steal confidential information, install ransomware or pivot to the internal network.","JetBrains TeamCity is affected by a Remote Code Execution vulnerability. The root cause of this vulnerability is the existence of an alternate access path that does not have authentication checks. More exactly, an attacker can access the \u003Ccode>\u002Fapp\u002Frest\u002Fusers\u002Fid:1\u002Ftokens\u002FRPC2\u003C\u002Fcode> path, which requires no authentication, to obtain an authentication token, which can be further used to have unrestricted access to the API exposed by TeamCity. Afterwards, using this token an attacker can enable the possiblity to remoteley execute code on the target.","Update TeamCity to the latest available version.","We recommend to update TeamCity to the latest available version.",[65],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2023-42793",9.8,0.99987,0.99984,[70],"CVE-2023-42793","2023-09-19T00:00:00Z","Build Management","JetBrains","TeamCity",[76],"RCE","NETSCAN-SNIPER-CVE-2023-42793","JetBrains TeamCity - Remote Code Execution","2023-10-24T00:00:00Z",["Island",81],{"key":82,"params":83,"result":85},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":84},"{}",{"head":86},{},["Island",88],{"key":89,"params":90,"result":91},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":84},{"head":92},{},["Island",94],{"key":95,"params":96,"result":98},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":97},"{\"text-color\":\"gray\"}",{"head":99},{}]