CVE-2020-35667 is a server-side request forgery vulnerability affecting JetBrains TeamCity Plugin versions before 2020.2.85695. The flaw allows a remote attacker to induce the vulnerable TeamCity component to issue server-side network requests to attacker-controlled or attacker-selected destinations. The available information indicates that exploitation is possible over the network with low attack complexity, requires no authentication or user interaction, and may expose user credentials. The documented impact profile is limited primarily to confidentiality loss rather than integrity or availability effects.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2020-35667, a credential interception vulnerability in the JetBrains TeamCity IntelliJ IDEA plugin. The exploit consists of a Python Flask server (poc_server.py) that mimics the TeamCity XML-RPC API. When the vulnerable plugin is configured to connect to this server (e.g., http://127.0.0.1:8888), the server responds to XML-RPC requests, provides a fake RSA public key, and captures the encrypted credentials sent by the plugin. The server then decrypts the password using its private key and logs both the username and password in plaintext. The repository includes detailed documentation (README.md, REPORT.md, ANALYSIS.md) explaining the vulnerability, the attack workflow, and reproduction steps. The main exploit capability is credential interception via a network-based attack vector, exploiting the lack of server authentication in the plugin's key exchange process. The only code file is poc_server.py, which implements the malicious server logic. The exploit does not target a specific IP or domain by default, but is designed to be run locally or on an attacker-controlled host.
This repository provides a proof-of-concept (PoC) for CVE-2020-35667, a Server-Side Request Forgery (SSRF) vulnerability in the IntelliJ IDEA TeamCity integration plugin. The exploit demonstrates how an attacker can leverage a lack of input validation in the plugin's local HTTP server to force it to make authenticated requests (with TeamCity credentials) to attacker-controlled endpoints, resulting in credential leakage. The repository is structured as follows: - `README.md`: Detailed documentation, including vulnerability analysis, reproduction steps, and security recommendations. - `pocartifacts/http-listener/`: Contains a minimal Flask-based HTTP server (`sink.py`) that logs all incoming requests to `sink.log`. This acts as the attacker's endpoint to capture exfiltrated credentials. Includes a Dockerfile and requirements for easy setup. - `pocartifacts/tc-server/`: Contains a Dockerfile and entrypoint script to set up a local TeamCity server for testing the exploit. The main exploit flow is: 1. The attacker sends a crafted HTTP request to the vulnerable plugin's local endpoint, setting the `file` parameter to an attacker-controlled URL (e.g., `http://localhost:8000/`). 2. The plugin, running on the developer's machine, makes an HTTP request to this URL, including TeamCity credentials in the headers. 3. The attacker's HTTP sink logs the incoming request, capturing the credentials. The PoC is operational and demonstrates the vulnerability in a controlled lab environment using Docker containers. No weaponized payload is included, but the exploit is functional and can be used to verify the vulnerability and credential leakage.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability affecting JetBrains TeamCity, referenced by CVE-2020-35667, with publicly available exploits according to the plugin metadata.
A prior TeamCity SSRF vulnerability mentioned as historical architectural context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.