PT-2023-8748 · Jetbrains · Jetbrains Teamcity+1
Published
2023-03-04
·
Updated
2026-06-01
·
CVE-2024-27198
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JetBrains TeamCity versions prior to 2023.11.4
Description
JetBrains TeamCity contains an authentication bypass issue due to an alternative path vulnerability. Successful exploitation allows an unauthenticated attacker to perform any action, including creating a user with system administrator privileges. Publicly available exploits exist. This vulnerability has been actively exploited in the wild, with reports of ransomware attacks and DDoS activity. The vulnerability allows attackers to bypass authentication checks and gain administrative access to the server. The payload for exploitation involves a specific request:
/hax?jsp=/app/rest/server;.jsp. APT29 has been observed exploiting this vulnerability.Recommendations
Update JetBrains TeamCity to version 2023.11.4 or later.
Exploit
Fix
RCE
Authentication Bypass Using an Alternate Path or Channel
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetbrains Teamcity
Teamcity