/CVE-2024-27198

PoC about CVE-2024-27198

Primary LanguagePython

CVE-2024-27198

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions in TeamCity server, an attacker can take full control over all TeamCity projects, builds, agents and artifacts, finally the attacker will perfomn a RCE.

Download

git clone https://github.com/jrbH4CK/CVE-2024-27198.git
cd CVE-2024-27198

PoC

To create an account as admin privileges inside the server

python3 cve-2024-27198.py http://example.com username password

Demo:

Account creation

Texto alternativo

User roles

Texto alternativo

Additional notes