RULE(RULE ID:337849)

Rule General Information
Release Date: 2024-03-06
Rule Name: JetBrains TeamCity Authentication Bypass Vulnerability (CVE-2024-27198)
Severity:
CVE ID:
Rule Protection Details
Description: JetBrains TeamCity is a set of distributed build management and continuous integration tools from the Czech company JetBrains. The tool provides features such as continuous unit testing, code quality analysis, and build problem analysis reports. Versions prior to JetBrains TeamCity 2023.11.4 have an authentication bypass vulnerability that allows a remote attacker to construct a malicious URL to bypass authentication checks, allowing direct access to the endpoint that requires authentication. A remote attacker could exploit this vulnerability to cause an RCE, create an administrator account, and take full control of a vulnerable TeamCity server, and could further exploit it to cause a supply chain attack.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference: https://cxsecurity.com/cveshow/CVE-2024-27198/
Solutions
Refer to the announcement or patch by the vendor: https://www.jetbrains.com/help/teamcity/previous-releases-downloads.html