CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
Other sources
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2023.11.4 - Compensating control
Apply mitigations as provided by the vendor; follow applicable BOD 22-01 guidance for cloud services; discontinue use of JetBrains TeamCity if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27199?
CVE-2024-27199 is classified as a medium severity vulnerability due to its potential for limited admin actions via path traversal.
How do I fix CVE-2024-27199?
To fix CVE-2024-27199, you must upgrade JetBrains TeamCity to version 2023.11.4 or later.
What type of vulnerability is CVE-2024-27199?
CVE-2024-27199 is a path traversal vulnerability that allows unauthorized access to limited administrative actions.
Which versions of JetBrains TeamCity are affected by CVE-2024-27199?
CVE-2024-27199 affects all versions of JetBrains TeamCity prior to 2023.11.4.
Can CVE-2024-27199 be exploited remotely?
Yes, CVE-2024-27199 can be exploited remotely if the attacker has network access to the vulnerable JetBrains TeamCity instance.