JetBrains TeamCity Mass Exploitation Underway, Rogue Accounts Thrive (www.darkreading.com)
from IllNess@infosec.pub to securitynews@infosec.pub on 08 Mar 2024 06:57
https://infosec.pub/post/9415392

One of the vulnerabilities (identified as CVE-2024-27198) has a near-maximum severity CVSS rating of 9.8 out of 10 and is an authentication bypass issue in TeamCity’s Web component. Researchers from Rapid7 who discovered the vulnerability and reported it to JetBrains have described it as enabling a remote unauthenticated attacker to execute arbitrary code to take complete control of affected instances.

#securitynews

threaded - newest