PT-2023-8748 · Jetbrains · Jetbrains Teamcity+1

CVE-2024-27198

·

Published

2023-03-04

·

Updated

2026-09-05

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2023.11.4
Description An authentication bypass exists due to an error in the server request processing procedure, allowing an unauthenticated remote attacker to bypass authentication checks via an alternative path or channel. This flaw enables the attacker to perform administrative actions, including the creation of system administrator users and the execution of arbitrary code with elevated privileges. Real-world incidents have shown attackers exploiting this issue to gain admin access to servers, extract AWS IAM credentials from backup data, and perform lateral movement into cloud infrastructure and internal CI/CD environments.
Recommendations Update JetBrains TeamCity to version 2023.11.4 or later. Audit TeamCity audit logs for unauthorized admin account creation or unexpected configuration changes. Rotate all secrets, API keys, and AWS credentials that were active in pipelines.

Exploit

Fix

RCE

Relative Path Traversal

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01792
BDU:2024-02014
CVE-2024-27198

Affected Products

Jetbrains Teamcity
Teamcity