Lucene search

K
cisa_kevCISACISA-KEV-CVE-2024-27198
HistoryMar 07, 2024 - 12:00 a.m.

JetBrains TeamCity Authentication Bypass Vulnerability

2024-03-0700:00:00
CISA
www.cisa.gov
21
jetbrains
teamcity
authentication bypass
vulnerability
admin actions

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

Low

EPSS

0.969

Percentile

99.8%

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

Low

EPSS

0.969

Percentile

99.8%