CVE-2024-27198

Scores

EPSS Score

0.9458

CVSS

3.x 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All CVSS Scores

CVSS 4.0
0.0
CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
0.0

Description

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Sources

nvd

CWEs

CWE-288

Related Vulnerabilities

Exploits

Vulnerable Software

Type: Configuration

Vendor: jetbrains

Product: teamcity

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
      "versionEndExcluding": "2023.11.4",
      "vulnerable": true
    }
  ],
  "operator": "OR"
}

Source: nvd