CVE-2024-27199
9.5 CISA KEVJetBrains · TeamCity
A relative path traversal vulnerability in JetBrains TeamCity allows unauthenticated attackers to perform limited administrative actions.
Executive summary
A critical path traversal vulnerability in JetBrains TeamCity is currently undergoing mass exploitation in the wild, leading to the creation of rogue accounts and potential ransomware deployment.
Vulnerability
The vulnerability is a relative path traversal flaw in the web interface that allows unauthenticated attackers to bypass authentication and execute sensitive administrative functions.
Business impact
The CVSS score of 9.5 underscores the critical nature of this vulnerability. Because it allows unauthenticated administrative access, it is a prime target for threat actors. Successful exploitation has been linked to the deployment of ransomware, cryptocurrency miners, and the creation of backdoors within development environments.
Remediation
Immediate Action: Upgrade all JetBrains TeamCity instances to version 2023.11.4 or later immediately.
Proactive Monitoring: Review TeamCity audit logs for the creation of new administrative users or unusual system configuration changes that may indicate a compromise.
Compensating Controls: Ensure that TeamCity instances are not accessible from the public internet and utilize network segmentation to isolate the build environment.
Exploitation status
Public Exploit Available: Yes (PoC available on GitHub).
Analyst recommendation
Given the history of mass exploitation and the availability of PoC code, this vulnerability represents an urgent threat to any organization using TeamCity. Immediate patching is the only effective way to prevent unauthorized access and potential ransomware infection. Organizations should also perform a thorough security audit of their TeamCity servers to identify any signs of existing unauthorized access.