Skip to content
COOEY

EXPOSURES › CVE-2024-27198

CVE-2024-27198

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-03-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-27198 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildauth-bypass

An authentication bypass in JetBrains TeamCity lets attackers perform admin actions without valid credentials.

This vulnerability allows unauthenticated attackers to escalate privileges and execute administrative commands on TeamCity servers, directly impacting CI/CD pipelines used by defense contractors. DIB organizations must patch TeamCity immediately and audit for unauthorized admin access, as this bypasses standard authentication controls and could lead to supply-chain compromise or data exfiltration.

Shame score — An authentication bypass enabling admin actions is a severe, avoidable flaw that undermines core security controls and is actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.