Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

New critical JetBrains security flaw could let hackers hijack entire servers

A padlock against a black computer screen.

Cybersecurity researchers have recently discovered two high severity vulnerabilities in JetBrains TeamCity On-Premises software. 

The software is described as a “powerful and user-friendly Continuous Integration and Deployment server”, that developers can use to build, check, and run automated tests on servers before committing changes. The vulnerabilities, according to the experts from Rapid7 who discovered them, could be used to fully take over vulnerable systems, launch Distributed Denial of Service (DDoS) attacks, and more.

The first one is tracked as CVE-2024-27198, and carries a severity score of 9.8, making it critical. It is described as an authentication bypass, allowing remote unauthenticated attackers to fully take over target servers: "Compromising a TeamCity server allows an attacker full control over all TeamCity projects, builds, agents and artifacts, and as such is a suitable vector to position an attacker to perform a supply chain attack," the researchers warned.

Defending against Russian and North Korean state-sponsored threat actors

The second flaw is tracked as CVE-2024-27199, and carries a severity score of 7.3. This authentication bypass flaw can be used to mount DDoS attacks against the TeamCity server, as well as adversary-in-the-middle attacks. 

"This authentication bypass allows for a limited number of authenticated endpoints to be reached without authentication," Rapid7 said. “An unauthenticated attacker can leverage this vulnerability to both modify a limited number of system settings on the server, as well as disclose a limited amount of sensitive information from the server."

All versions up to 2023.11.3 were said to be vulnerable. JetBrains released a patch earlier this month, and urged all users to upgrade their software to version 2023.11.4. 

According to The Hacker News, JetBrains TeamCity users have become a popular target among North Korean and Russian threat actors, which is why the company urged them to apply the patch without delay. 

More from TechRadar Pro

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.