QID 379449

Date Published: 2024-03-05

QID 379449: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (TW-86500, TW-86502)

JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.

JetBrains TeamCity contains the following vulnerabilities:

  • CVE-2024-27198: Authentication bypass allowing to perform administrative actions.
  • CVE-2024-27199: Path traversal allowing to perform limited administrative actions.
Affected Versions:
JetBrains TeamCity prior to 2023.11.4

QID Detection Logic (Unauthenticated):
QID checks for vulnerable versions of installed TeamCity in the system.

QID Detection Logic (Authenticated): It checks for the version of TeamCity installed via registry path in windows and directory in unix
NOTE: Authenticated check is potential as checking security patch plugin information is not supported

Successful exploitation of the vulnerabilities could allow an unauthenticated, remote attacker to bypass security restrictions and perform administrative actions on a targeted system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to JetBrains vendor advisory JetBrains TeamCity Security Advisory (TW-86500, TW-86502) for information pertaining to these vulnerabilities.

    CVEs related to QID 379449

    Software Advisories
    Advisory ID Software Component Link
    JetBrains TeamCity URL Logo www.jetbrains.com/privacy-security/issues-fixed/