logo

Authentication bypass vulnerabilities in TeamCity: everything you need to know

ID: 1a6c460a-420d-5092-b02e-5e14be664190

STIX ID: report--1a6c460a-420d-5092-b02e-5e14be664190

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2024-03-06

Date Updated: 2026-05-01

...
...

JetBrains released patches for two critical TeamCity authentication-bypass vulnerabilities (CVE-2024-27198 — CVSS 9.8 — and CVE-2024-27199 — CVSS 7.3) that allow unauthenticated HTTP(S) access to bypass authentication and gain administrative control or modify sensitive settings; exploitation has been observed in the wild, CISA added CVE-2024-27198 to its Known Exploited Vulnerabilities catalog, and affected on-prem TeamCity versions should be updated to 2023.11.4 or mitigated with the vendor's security patch plugin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.