CVE-2024-56348:
JetBrains TeamCity Authentication Bypass + RCE
CVE-2024-56348 is a critical authentication bypass vulnerability in JetBrains TeamCity on-premises affecting all versions prior to 2024.12. The REST API improperly handles requests to paths containing ;.jsp, allowing an unauthenticated attacker to invoke any REST endpoint as if fully authenticated.
This exploit chains the bypass with TeamCity's own REST API to create a SYSTEM_ADMIN account, mint an API token, and achieve full remote code execution — either through the built-in debug endpoint or a dynamically uploaded JSP plugin webshell. No credentials required.
Affected versions: JetBrains TeamCity on-premises < 2024.12
4.3
Medium risk
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Compexity
low
Privileges
low
Affected
< 2024.12
Patched
>= 2024.12