Summary:
A critical vulnerability, identified as CVE-2024-27198, has been discovered in the TeamCity On-Premises CI/CD solution developed by JetBrains. This vulnerability poses a significant threat as it allows remote, unauthenticated attackers to seize control of the server with administrative privileges. The exploit details for CVE-2024-27198 are publicly available, underscoring the urgency for swift action to mitigate potential exploitation and prevent unauthorized access to sensitive systems. In addition to CVE-2024-27198, JetBrains addressed another security issue, denoted as CVE-2024-27199, in the latest version release of TeamCity On-Premises. While this vulnerability is considered less severe, it still warrants attention from administrators due to its potential impact. CVE-2024-27199 enables attackers to manipulate a limited set of system settings without authentication, facilitating the creation of new administrator accounts or generation of administrator access tokens.[/subscribe_to_unlock_form]
Summary:
A critical vulnerability, identified as CVE-2024-27198, has been discovered in the TeamCity On-Premises CI/CD solution developed by JetBrains. This vulnerability poses a significant threat as it allows remote, unauthenticated attackers to seize control of the server with administrative privileges. The exploit details for CVE-2024-27198 are publicly available, underscoring the urgency for swift action to mitigate potential exploitation and prevent unauthorized access to sensitive systems. In addition to CVE-2024-27198, JetBrains addressed another security issue, denoted as CVE-2024-27199, in the latest version release of TeamCity On-Premises. While this vulnerability is considered less severe, it still warrants attention from administrators due to its potential impact. CVE-2024-27199 enables attackers to manipulate a limited set of system settings without authentication, facilitating the creation of new administrator accounts or generation of administrator access tokens.[emaillocker id="1283"]
Recommendations:
References:
The following reports contain further technical details:
[/emaillocker]