CVE-2024-31136: high-severity vulnerability in JetBrains TeamCity
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
TeamCity versions before 2024.03 had a flaw where two-factor authentication (2FA) could be bypassed by crafting a special URL parameter. This is serious because it allows attackers to gain unauthorized access to accounts even when 2FA is enabled.
A URL parameter validation bypass in TeamCity before 2024.03 allowed attackers to circumvent two-factor authentication enforcement during the authentication flow. The attack requires network access to the vulnerable TeamCity instance but no prior authentication; successful exploitation grants full user account access, including administrative privileges depending on the compromised account.
In the same product, most dangerous first.