CVE-2024-27199
KEV RANSOMWAREHIGH 7.3EPSS 100.0%
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- CVSS v3.1
- 7.3 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - CVSS v3.1
- 7.3 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - EPSS
- 99.99% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-04-20, used in ransomware campaigns
- Nuclei
- high · CWE-23
- Published
- 2024-03-04
- Updated
- 2026-04-21
Proof-of-concept exploits (5)
- https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitati…
- Stuub/RCity-CVE-2024-2719835★ · 2024-07-19
- W01fh4cker/CVE-2024-27198-RCE154★ · 2024-03-11
- chebuya/CVE-2024-30851-jasmin-ransomware-path-traversal-poc21★ · 2024-04-09
- chengbochuan3/CVE-CICD-Security