logo

Critical JetBrains TeamCity On-Premises Flaws Could Lead to Server Takeovers

ID: 858c45db-8a79-5b66-9532-49caccf5630b

STIX ID: report--858c45db-8a79-5b66-9532-49caccf5630b

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-03-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Two critical authentication-bypass vulnerabilities (CVE-2024-27198 CVSS 9.8 and CVE-2024-27199 CVSS 7.3) have been disclosed in JetBrains TeamCity On-Premises affecting versions through 2023.11.3; they allow unauthenticated attackers to gain administrative control or replace HTTPS certificates/change ports, enabling full server compromise, supply-chain attacks, denial-of-service, or MITM scenarios. Rapid7 discovered the issues and JetBrains released fixes in version 2023.11.4; TeamCity Cloud was already patched. Administrators are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.