CVE-2024-27198: In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

9.8 CVSS

Description

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Classification

CVE ID: CVE-2024-27198

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

Vendor: JetBrains

Product: TeamCity

Nuclei Template

http/cves/2024/CVE-2024-27198.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 97.03% (probability of being exploited)

EPSS Percentile: 99.87% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://www.jetbrains.com/privacy-security/issues-fixed/
https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thrive

Timeline