Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

JetBrains TeamCity Relative Path Traversal Authentication Bypass

IdentifiersCVE-2024-27199CWE-23· Relative Path Traversal

CVE-2024-27199 is a relative path traversal vulnerability in JetBrains TeamCity On-Premises affecting versions through 2023.11.3 and fixed in 2023.11.4. The flaw stems from path traversal that permits unauthenticated access to a limited set of authenticated TeamCity endpoints over HTTP(S). Public reporting cited in the provided content states that exploitation can reach administrative HTTPS configuration functionality, including the "/app/https/settings/uploadCertificate" endpoint, allowing an attacker to replace the server HTTPS certificate with one of their choosing and alter the HTTPS service port. The issue therefore functions as a limited authentication bypass tied to improper path handling, enabling unauthorized administrative actions and limited disclosure of sensitive information.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to perform limited administrative actions on a vulnerable TeamCity server. Reported impacts include replacing the HTTPS certificate, changing the HTTPS listening port, modifying a limited number of system settings, and disclosing a limited amount of sensitive information. Operationally, this can cause denial of service by breaking HTTPS access or moving the service to a different port, and may enable adversary-in-the-middle scenarios if clients trust an attacker-supplied certificate. Multiple sources in the provided content also note active exploitation in the wild, including use against build servers, with downstream risk to software delivery environments and possible credential exposure.

Mitigation

If you can’t patch tonight, do this now.

Until patching is completed, restrict HTTP(S) access to TeamCity management interfaces to trusted networks only, remove or tightly limit internet exposure, and monitor for requests to suspicious paths associated with this flaw, especially "/app/https/settings/" endpoints and other unexpectedly reachable authenticated URIs. Because exploitation has been observed in the wild, review TeamCity configuration for unauthorized HTTPS certificate changes, unexpected port changes, newly created accounts, and other suspicious administrative modifications. If compromise is suspected, treat the server as potentially exposed and rotate credentials and secrets accessible from TeamCity.

Remediation

Patch, then assume compromise.

Upgrade JetBrains TeamCity On-Premises to version 2023.11.4 or later. The provided content states that all On-Premises versions through 2023.11.3 are affected and that JetBrains fixed the issue in 2023.11.4; TeamCity Cloud instances were already patched. Organizations should also follow JetBrains vendor instructions and, if mitigations cannot be applied, discontinue use of exposed vulnerable instances until patched.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
JetbrainsTeamcityapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware4

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity10

Community discussion across Reddit, Mastodon, and other social sources.