JetBrains TeamCity Auth Bypass Vulnerability Exploited
ID: 89e69791-0cd5-50ea-b12c-ef527882f6fa
STIX ID: report--89e69791-0cd5-50ea-b12c-ef527882f6fa
Feed Name: Cyble Blog
On March 4, 2024 JetBrains released patches for two authentication-bypass vulnerabilities in TeamCity (CVE-2024-27198 — critical, and CVE-2024-27199 — high); Rapid7 published details and public exploits soon after, and Cyble observed active exploitation of CVE-2024-27198 from March 5, 2024 onward. The report notes 1,780 internet-exposed TeamCity instances, captured exploitation attempts in sensor data, a set of IoCs (multiple attacker IPs), and underground forum activity selling compromised TeamCity access; it recommends immediate patching, network segmentation, monitoring of TeamCity logs, and regular assessments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
