CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerability
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
Other sources
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2023.11.4 - Compensating control
Discontinue use of JetBrains TeamCity if mitigations are unavailable
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27198?
CVE-2024-27198 is classified as a critical authentication bypass vulnerability in JetBrains TeamCity.
How do I fix CVE-2024-27198?
To fix CVE-2024-27198, update JetBrains TeamCity to version 2023.11.4 or later.
What actions can be performed by exploiting CVE-2024-27198?
Exploitation of CVE-2024-27198 allows an attacker to perform administrative actions without proper authentication.
Which versions of JetBrains TeamCity are affected by CVE-2024-27198?
CVE-2024-27198 affects all versions of JetBrains TeamCity prior to 2023.11.4.
How can I determine if my JetBrains TeamCity installation is vulnerable to CVE-2024-27198?
Check the version of your JetBrains TeamCity installation to see if it's below version 2023.11.4 to determine vulnerability to CVE-2024-27198.