LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 28, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-27198 to its Known Exploited Vulnerabilities catalog on Mar 7, 2024, with a federal patch deadline of Mar 28, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

CVE-2024-27198 is an authentication bypass vulnerability in JetBrains TeamCity that lets an unauthenticated attacker perform administrative actions. Because TeamCity often sits at the center of build and deployment pipelines, successful abuse can give an attacker control over source code, credentials, and release processes. CISA notes known ransomware use of this issue, so organizations running TeamCity should treat it as high priority and confirm all details against the vendor advisory.

This guidance is for IT and security teams. It stays within publicly stated facts: the product, the CWE class, the ability to perform admin actions, and the ransomware association. Exact versions, scores, and exploit steps are not listed here; always verify them in the JetBrains advisory.

How it works

The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In plain terms, the product fails to enforce authentication correctly on certain paths or channels, so an attacker can reach functionality that should require a valid admin session.

Once past the authentication check, the attacker can perform administrative actions. Those actions typically include creating or modifying users, changing project settings, installing plugins, or accessing build configurations and secrets. No further exploit mechanics are described in the provided facts; defenders should treat any unauthenticated request that results in admin-level state changes as a potential indicator and confirm the precise attack surface against the vendor advisory.

Am I affected? How to find it in your systems

JetBrains TeamCity is a continuous-integration and continuous-delivery server commonly deployed on-premises or in private clouds to orchestrate builds, tests, and deployments. It is often reachable on internal networks or, less commonly, exposed to the internet.

How to remediate

Patch first. Apply the vendor-supplied update for TeamCity exactly as described in the JetBrains advisory. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls.

If your data may have been exposed

Actively exploited authentication-bypass flaws, especially those linked to ransomware, frequently lead to credential theft, source-code exfiltration, or full environment compromise. Assume that any secrets stored in TeamCity (tokens, certificates, cloud credentials) may have been accessed. Rotate them, review build and deployment logs for unauthorized changes, and examine downstream systems for lateral movement. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedJetBrains · TeamCity
WeaknessCWE-288
Added to CISA KEVMar 7, 2024
Federal patch deadlineMar 28, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities