Hackers have started to exploit the critical-severity authentication bypass vulnerability (CVE-2024-27198) in TeamCity On-Premises, which JetBrains addressed in an update on Monday. Exploitation appears to be massive, with hundreds of new users created on unpatched instances of TeamCity exposed on the public web. LeakIX, a search engine for exposed device misconfigurations and vulnerabilities, told BleepingComputer that a little over 1,700 TeamCity servers have yet to receive the fix. Most of the vulnerable hosts indexed by LeakIX are in Germany, the United States, and Russia, followed at a distance by China, the Netherlands, and France. Of these, the platform indicates that hackers have already compromised more than 1,440 instances. "There are between 3 and 300 hundreds users created on compromised instances, usually the pattern is 8 alphanum characters," LeakIX told BleepingComputer. GreyNoise, a company that analyzes internet scanning traffic, also recorded on March 5 a sharp increase in attempts to exploit CVE-2024-27198. According to GreyNoise statistics, most attempts come from systems in the United States on the DigitalOcean hosting infrastructure. Gregory Boddin of LeakIX told BleepingComputer that the TeamCity servers observed are production machines used to build and deploy software. This means that compromising them could lead to supply-chain attacks as they may contain sensitive details such as credentials for the environments where code is deployed, published, o...
TeamCity auth bypass bug exploited to mass-generate admin accounts
Affected Software
Frequently Asked Questions
Which TeamCity deployments are affected by the exploitation?
The activity targets unpatched TeamCity On-Premises instances exposed on the public web. LeakIX reported that a little over 1,700 TeamCity servers had not yet received the fix.
What are attackers doing after exploiting CVE-2024-27198?
Attackers are creating large numbers of new users, including administrator accounts, on compromised instances. LeakIX observed between 3 and 300 users created per compromised instance, commonly with eight-character alphanumeric usernames.
How widespread is the reported compromise?
LeakIX indicated that more than 1,440 of the vulnerable instances it indexed had already been compromised. The largest concentrations of vulnerable hosts were in Germany, the United States, and Russia, followed by China, the Netherlands, and France.
What evidence indicates active exploitation?
GreyNoise recorded a sharp increase in exploitation attempts on March 5. Its statistics showed that most observed attempts originated from systems in the United States using DigitalOcean hosting infrastructure.
What action does the article imply for TeamCity administrators?
Administrators of internet-exposed TeamCity On-Premises servers should apply JetBrains' update addressing CVE-2024-27198. They should also check for newly created accounts, particularly suspicious eight-character alphanumeric usernames.