CVE-2024-27199

high

Description

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

References

https://www.hivepro.com/threat-advisory/teamcity-vulnerabilities-unleash-jasmin-ransomware-and-more/

https://www.trendmicro.com/en_us/research/24/c/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware.html?&web_view=true

https://therecord.media/jetbrains-rapid7-silent-patching-dispute?&web_view=true

https://www.hivepro.com/threat-digest/attacks-vulnerabilities-and-actors-4-to-10-march-2024/

https://thecyberthrone.in/2024/03/10/thecyberthrone-security-week-in-review-march-9-2024/

https://securityaffairs.com/160236/security/jetbrains-teamcity-bug-cisa-known-exploited-vulnerabilities-catalog.html

https://blog.detectify.com/product-updates/significant-changes-to-attack-surface-overview-and-many-new-tests/

https://www.theregister.com/2024/03/07/teamcity_exploits_lead_to_ransomware/

https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive

https://www.hivepro.com/threat-advisory/critical-vulnerabilities-discovered-in-teamcity-enable-server-takeover/

https://thecyberthrone.in/2024/03/05/critical-teamcity-vulnerabilities-patched-cve-2024-27198-cve-2024-27199/

https://www.theregister.com/2024/03/05/rapid7_jetbrains_vuln_disclosure_dispute/

https://securityaffairs.com/159995/security/jetbrains-teamcity-flaws.html

https://www.bleepingcomputer.com/news/security/exploit-available-for-new-critical-teamcity-auth-bypass-bug-patch-now/?&web_view=true

https://www.bleepingcomputer.com/news/security/exploit-available-for-new-critical-teamcity-auth-bypass-bug-patch-now/

https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/

https://www.jetbrains.com/privacy-security/issues-fixed/

https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive

Details

Source: Mitre, NVD

Published: 2024-03-04

Updated: 2024-03-11

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity: High