logo

Rapid7 throws JetBrains under the bus for 'uncoordinated vulnerability disclosure'

ID: 57560eda-f8b3-5f1e-9019-89868511d3a9

STIX ID: report--57560eda-f8b3-5f1e-9019-89868511d3a9

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-03-05

Date Updated: 2026-04-26

Author: Connor Jones

...
...

This report describes two critical authentication-bypass vulnerabilities in JetBrains TeamCity (CVE-2024-27198 and CVE-2024-27199), Rapid7's dispute with JetBrains over silent patching and coordinated disclosure, and evidence from third parties that exploitation began rapidly after the fixes were released; on-prem TeamCity instances up to 2023.11.3 are affected while cloud instances were already patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.