Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a major security issue affecting JetBrains TeamCity On-Premises software to its list of known exploited vulnerabilities (KEV).
The vulnerability, identified as CVE-2024-27198 (CVSS score: 9.8), is related to an authentication bypass flaw that lets a remote, unauthorized attacker fully take control of a vulnerable server.
Alongside CVE-2024-27199 (CVSS score: 7.3), a moderate-severity authentication bypass vulnerability that permits a “limited amount” of information leakage and system modification, JetBrains patched it earlier this week.
The business stated at the time that the vulnerabilities might allow an unauthorized attacker with HTTP(S) access to a TeamCity server read more CISA Warns of Actively Exploited JetBrains TeamCity Vulnerability.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
