PT-2023-8748 · Jetbrains · Jetbrains Teamcity+1
CVE-2024-27198
·
Published
2023-03-04
·
Updated
2026-09-05
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JetBrains TeamCity versions prior to 2023.11.4
Description
An authentication bypass exists due to an error in the server request processing procedure, allowing an unauthenticated remote attacker to bypass authentication checks via an alternative path or channel. This flaw enables the attacker to perform administrative actions, including the creation of system administrator users and the execution of arbitrary code with elevated privileges. Real-world incidents have shown attackers exploiting this issue to gain admin access to servers, extract AWS IAM credentials from backup data, and perform lateral movement into cloud infrastructure and internal CI/CD environments.
Recommendations
Update JetBrains TeamCity to version 2023.11.4 or later.
Audit TeamCity audit logs for unauthorized admin account creation or unexpected configuration changes.
Rotate all secrets, API keys, and AWS credentials that were active in pipelines.
Exploit
Fix
RCE
Relative Path Traversal
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetbrains Teamcity
Teamcity