The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated its warning on a critical JetBrains TeamCity flaw, confirming that ransomware operators are now actively exploiting the vulnerability to seize control of software development pipelines. The agency has added CVE-2023-42793 to its Known Exploited Vulnerabilities (KEV) catalog, transforming recommended updates into a mandatory, urgent directive for federal agencies and a stark alert for all organizations using the software.
The flaw, which affects TeamCity versions prior to 2023.05.4, carries a maximum severity CVSS score of 10.0. It allows an unauthenticated attacker to gain full administrative control of a TeamCity server. The danger is amplified by TeamCity's central role in continuous integration and continuous deployment (CI/CD) workflows. Control of this infrastructure is a powerful gateway for attackers to manipulate source code, inject malicious payloads into builds, and launch cascading supply chain attacks across an entire organization and its customers.
JetBrains released a patch for the vulnerability in July, but the critical window between fix and deployment has proven to be the real vulnerability. Ransomware groups have been weaponizing this delay, using their administrative access for maximum impact. Reports indicate they are using the foothold not just for initial compromise but to deploy ransomware across entire development and production environments from a single point of entry.
This attack pattern underscores a strategic shift in ransomware tactics. Threat actors are increasingly targeting high-leverage DevOps and build infrastructure, recognizing that compromising a CI/CD pipeline like TeamCity offers a direct path to widespread infection. The primary exploited weakness is now the internal "patch gap" between the availability of a security fix and its implementation.
For development and security teams, CISA's message leaves no room for ambiguity. There are no viable workarounds. The following actions are now critical priorities: 1. Audit all infrastructure for installations of JetBrains TeamCity. 2. Identify every instance running a version prior to 2023.05.4. 3. Apply the official patch from JetBrains immediately, treating it as a production-halting emergency. 4. Assume any unpatched instance has already been compromised and initiate a forensic investigation for malicious activity.
Global cybersecurity authorities are unequivocal: with ransomware gangs in active exploitation, delaying this update is a direct invitation to a severe breach. Organizations must refer to JetBrains' security advisories for specific patching guidance and take immediate action to secure their development pipelines.
美國網絡安全和基礎設施安全局(CISA)已就 JetBrains TeamCity 的一個關鍵漏洞發出更強烈警告,確認勒索軟件操控者現正積極利用此漏洞,以奪取軟件開發管道的控制權。該局已將 CVE-2023-42793 加入其已知被利用漏洞目錄,將原本的更新建議轉變為針對聯邦機構的強制性緊急指令,同時對所有使用該軟件的組織發出明確警示。
此漏洞影響 2023.05.4 之前的 TeamCity 版本,CVSS 嚴重程度評分為最高級別的 10.0。它允許未經身份驗證的攻擊者取得 TeamCity 伺服器的完整管理員控制權。由於 TeamCity 在持續整合與持續部署(CI/CD)工作流程中扮演核心角色,其危險性被進一步放大。掌控此基礎設施成為攻擊者的強力途徑,可藉此操縱源代碼、將惡意載荷注入構建過程,並對整個組織及其客戶發動連鎖供應鏈攻擊。
JetBrains 曾於去年七月發布此漏洞的補丁,但從修補到部署之間的關鍵窗口期已證明才是真正的薄弱環節。勒索軟件組織一直在利用這個延遲,將其管理員權限用於造成最大影響。報告指出,他們不僅利用此立足點進行初步入侵,更藉此單一入口點將勒索軟件部署至整個開發及生產環境。
此攻擊模式凸顯了勒索軟件戰術的策略性轉變。威脅行為者日益瞄準高槓桿的 DevOps 及構建基礎設施,認識到入侵像 TeamCity 這樣的 CI/CD 管道,能直接通往大規模感染。現時主要利用的弱點是安全修補程式發布與實際實施之間的內部「修補空窗期」。
對於開發及保安團隊而言,CISA 的信息毫無模糊空間。目前不存在任何可行的替代方案。以下行動現已成為關鍵優先事項: 1. 審計所有基礎設施,檢查是否安裝了 JetBrains TeamCity。 2. 識別所有運行版本低於 2023.05.4 的實例。 3. 立即套用 JetBrains 發佈的官方補丁,將其視為會導致生產環境停頓的緊急情況處理。 4. 假設任何未修補的實例已遭入侵,並啟動法證調查以偵測惡意活動。
全球網絡安全當局態度明確:在勒索軟件組織積極利用漏洞的情況下,延遲更新此補丁等同直接招致嚴重入侵。各組織應參閱 JetBrains 的保安公告以獲取具體修補指引,並立即採取行動保障其開發管道安全。
