TeamCity < 2023.11.4 - Authentication Bypass
Title source: nucleiDescription
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
Exploits (19)
exploitdb
WORKING POC
by İbrahimsql · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52411
nomisec
WORKING POC
155 stars
by W01fh4cker · remote
https://github.com/W01fh4cker/CVE-2024-27198-RCE
nomisec
WORKING POC
6 stars
by K3ysTr0K3R · remote
https://github.com/K3ysTr0K3R/CVE-2024-27198-EXPLOIT
nomisec
WORKING POC
1 stars
by CharonDefalt · remote
https://github.com/CharonDefalt/CVE-2024-27198-RCE
nomisec
WRITEUP
by ArtemCyberLab · poc
https://github.com/ArtemCyberLab/Project-Exploiting-CVE-2024-27198-RCE-Vulnerability
nomisec
WRITEUP
by HPT-Intern-Task-Submission · remote
https://github.com/HPT-Intern-Task-Submission/CVE-2024-27198
nomisec
WRITEUP
by Shimon03 · poc
https://github.com/Shimon03/Explora-o-RCE-n-o-autenticado-JetBrains-TeamCity-CVE-2024-27198-
metasploit
WORKING POC
EXCELLENT
by sfewer-r7 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2024_27198.rb
Nuclei Templates (1)
TeamCity < 2023.11.4 - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDk
Shodan:
http.component:"TeamCity" || http.title:teamcity || http.component:"teamcity"
FOFA:
title=teamcity
References (3)
Scores
CVSS v3
9.8
EPSS
0.9305
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+14 more repos
Details
CISA KEV
2024-03-07
VulnCheck KEV
2024-03-05
InTheWild.io
2024-03-07
ENISA EUVD
EUVD-2024-24437
Ransomware Use
Confirmed
CWE
CWE-288
Status
published
Products (1)
jetbrains/teamcity
< 2023.11.4
Published
Mar 04, 2024
KEV Added
Mar 07, 2024
Tracked Since
Feb 18, 2026