JetBrains TeamCity versions prior to 2024.12 suffer from an improper access control vulnerability that allows unauthorized users to view details of agents to which they should not have access. The flaw is due to insufficient enforcement of authorization checks when accessing agent details.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real Go-based exploit for CVE-2024-56348 affecting JetBrains TeamCity before 2024.12. The main exploit logic is concentrated in a single standalone file, cve-2024-56348.go, while the rest of the repository mostly provides documentation and a Dockerized lab environment for reproducing the issue against TeamCity 2023.11.3. The exploit is network-based and automates the full post-bypass chain. From the visible code, it first probes the unauthenticated REST bypass endpoint (/hax?jsp=/app/rest/server;.jsp) to verify exposure. It then abuses the same bypass to create a new SYSTEM_ADMIN user through /hax?jsp=/app/rest/users;.jsp, mints an API token for that user via /hax?jsp=/app/rest/users/id:<id>/tokens/<name>;.jsp, and retrieves a CSRF token from /authenticationTest.html?csrf. The remainder of the code, as indicated by function names and control flow, supports OS detection, arbitrary command execution, file read/write operations, and an interactive shell mode. If a debug-based execution path is unavailable, the tool falls back to deploying a JSP plugin shell and using that for command execution. That makes it more than a simple detector or proof-of-concept. Repository structure: the top level contains the exploit source, README, license, and policy files. The docker/ directory contains a lab environment with a Dockerfile, docker-compose.yml, shell scripts, and seeded TeamCity configuration. The Docker lab downloads TeamCity 2023.11.3, exposes it on port 8111, and pairs it with PostgreSQL 16. Many of the remaining files are TeamCity seed configuration, logging presets, and email notification templates; they support the lab but are not part of the exploit logic itself. Notable operational characteristics: the HTTP client disables TLS verification, uses a custom User-Agent string referencing the repository, stores cookies, and avoids following redirects automatically. The exploit is mature enough to be considered OPERATIONAL rather than a bare POC because it includes a complete exploitation workflow and multiple execution fallbacks, but it is not obviously part of a larger exploitation framework.
Repository contains an operational Go-based exploit for JetBrains TeamCity on-premises CVE-2024-56348 (auth bypass via `;.jsp` path handling) and a Docker lab to reproduce the issue. Core exploit logic is in `cve-2024-56348.go`: - Uses an HTTP client with cookie jar, disabled TLS verification, and no-follow redirects. - Confirms vulnerability by requesting `GET <target>/hax?jsp=/app/rest/server;.jsp` and checking for server/version markers. - Exploitation chain: 1) Creates a new user with `SYSTEM_ADMIN` role via `POST <target>/hax?jsp=/app/rest/users;.jsp` (JSON body). 2) Mints an API token for that user via `POST <target>/hax?jsp=/app/rest/users/id:<id>/tokens/<name>;.jsp`. 3) Fetches CSRF token via `POST <target>/authenticationTest.html?csrf` with `Authorization: Bearer <token>`. 4) Achieves RCE either through a TeamCity debug execution endpoint (when available) or by uploading/deploying a malicious TeamCity plugin containing a JSP webshell (fallback). The tool then supports: - interactive pseudo-shell (default when no action flags are provided) - single command execution (`-command`) - reverse shell callback (`-shell -lhost -lport`) - file read (`-read-file`) - file write (`-write-file -file-content`) Repository structure highlights: - `.github/workflows/release.yml`: builds static binaries for multiple OS/architectures on GitHub releases. - `docker/`: self-contained vulnerable lab (TeamCity 2023.11.3 + PostgreSQL 16) with seeded TeamCity config and extensive default TeamCity config templates/logging configs. Dockerfile downloads TeamCity from JetBrains (with Wayback fallback) and exposes port 8111. Overall purpose: provide a PoC/weaponizable research tool demonstrating unauthenticated REST API access leading to full admin takeover and remote code execution on vulnerable TeamCity servers, plus a reproducible Docker environment for testing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.