• News/
  • darkreading-20240307225132

JetBrains TeamCity Mass Exploitation Underway, Rogue Accounts Thrive

Dark Reading
·
Published Mar 7, 2024
·
Updated

Attacks targeting two security vulnerabilities in the TeamCity CI/CD platform have begun in earnest just days after its developer, JetBrains, disclosed the flaws on March 3. The attacks include at least one campaign to distribute ransomware, and another in which a threat actor appears to be creating admin users on vulnerable TeamCity instances for potential future use. One of the vulnerabilities (identified as CVE-2024-27198) has a near-maximum severity CVSS rating of 9.8 out of 10 and is an authentication bypass issue in TeamCity's Web component. Researchers from Rapid7 who discovered the vulnerability and reported it to JetBrains have described it as enabling a remote unauthenticated attacker to execute arbitrary code to take complete control of affected instances. CVE-2024-27199, the other vulnerability that JetBrains disclosed, is a moderate-severity authentication bypass flaw in the same TeamCity Web component. It allows for a "limited amount" of information disclosure and system modification, according to Rapid7. Some 30,000 organizations use TeamCity to automate build, testing and deployment processes for software projects in CI/CD environments. Like other recent TeamCity flaws — such as CVE-2024-23917 in February 2024, and CVE-2023-42793, which Russia's Midnight Blizzard group used in attacks last year (it is also known for the infamous SolarWinds supply chain attacks), the two new ones have stoked considerable concern. The worries have to do with the potential for at...

Read full article

Affected Software

1 affected component
JetBrains TeamCity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What security vulnerabilities are being exploited in JetBrains TeamCity?

Two security vulnerabilities in the TeamCity CI/CD platform are currently being targeted by attackers.

2

What is the main issue discussed in the article regarding JetBrains TeamCity?

The article discusses a mass exploitation of vulnerabilities in JetBrains TeamCity, leading to the creation of rogue accounts.

3

What types of attacks are happening against JetBrains TeamCity users?

Attacks include ransomware distribution and the establishment of rogue accounts by threat actors.

4

When were the vulnerabilities in TeamCity disclosed by JetBrains?

JetBrains disclosed the vulnerabilities on March 3, just days before the reported mass exploitation began.

5

Who is primarily affected by these vulnerabilities in JetBrains TeamCity?

Users of the JetBrains TeamCity CI/CD platform are primarily affected by these exploitation campaigns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203