¡¾Îó²îͨ¸æ¡¿JetBrains TeamCityÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-27198£©
Ðû²¼Ê±¼ä 2024-03-05Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | JetBrains TeamCityÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î | ||
CVE ID | CVE-2024-27198 | ||
Îó²îÀàÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | ·¢Ã÷ʱ¼ä | 2024-03-05 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ֪ |
TeamCityÊÇJetBrainsÆìϵÄÒ»¿î¹¦Ð§Ç¿Ê¢µÄÒ»Á¬¼¯³É£¨Continuous Integration£¬£¬£¬£¬£¬£¬£¬¼ò³ÆCI£©¹¤¾ß£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ð§ÀÍÆ÷¶ËºÍ¿Í»§¶Ë¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬TeamCity ͨ¹ý HTTP ¶Ë¿Ú8111¹ûÕæWeb ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÑ¡ÔñÉèÖÃΪͨ¹ý HTTPS ÔËÐС£¡£¡£
2024Äê3ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøVSRC¼à²âµ½ TeamCity On-PremisesÖÐÐÞ¸´ÁËÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-27198£©£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îµÄϸ½Ú¼°PoC/EXPÒѹûÕæ¡£¡£¡£
TeamCity°æ±¾2023.11.4֮ǰÔÚTeamCity Web ×é¼þÖб£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬£¬¿É½á¹¹¶ñÒâURLÈÆ¹ýÉí·ÝÑéÖ¤¼ì²é£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÒÔÖ±½Ó»á¼ûÐèÒªÉí·ÝÑéÖ¤µÄ¶Ëµã¡£¡£¡£Ô¶³ÌÍþвÕß¿ÉʹÓøÃÎó²îµ¼ÖÂRCE¡¢Ð½¨ÖÎÀíÔ±ÕÊ»§²¢ÍêÈ«¿ØÖÆÒ×Êܹ¥»÷µÄ TeamCity ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄܽøÒ»²½Ê¹Óõ¼Ö¹©Ó¦Á´¹¥»÷¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬TeamCity Web ×é¼þÖл¹±£´æÒ»¸ö·¾¶±éÀúÎó²î£¨CVE-2024-27199£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö7.3£©£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓøÃÎó²îÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼ûijЩ¾ÓÉÉí·ÝÑéÖ¤µÄ¶Ëµã£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡¢ÐÞ¸ÄЧÀÍÆ÷ÉϵÄijЩϵͳÉèÖõȡ£¡£¡£
¶þ¡¢Îó²î¸´ÏÖ

Èý¡¢Ó°Ïì¹æÄ£
TeamCity£¨On-Premises£©< 2023.11.4
ËÄ¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½TeamCity£¨On-Premises£©°æ±¾2023.11.4£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓÃTeamCity ÖеÄ×Ô¶¯¸üÐÂÑ¡Ï£¬£¬£¬£¬£¬£¬Ò²¿ÉÊÖ¶¯ÏÂÔØ×°Öᣡ£¡£
ÏÂÔØÁ´½Ó£º
https://www.jetbrains.com/teamcity/download/other.html
3.2 ÔÝʱ²½·¥
ÈôÊÇÎÞ·¨¸üе½°æ±¾2023.11.4£¬£¬£¬£¬£¬£¬£¬¿ÉÓ¦ÓÃÇå¾²²¹¶¡²å¼þ£º
ÊÊÓÃÓÚTeamCity 2018.2¼°¸ü¸ß°æ±¾
ÊÊÓÃÓÚTeamCity 2018.1 ¼°Ö®Ç°°æ±¾
Îó²îÏêÇé¡¢IoCµÈ¸ü¶àÐÅÏ¢Ïê¼û²Î¿¼Á´½Ó¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/
https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now
Îå¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-03-05 | Ê×´ÎÐû²¼ |
Áù¡¢¸½Â¼
5.1 ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é
ÍòÀû¹ú¼Ê¹ÙÍø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÍòÀû¹ú¼Ê¹ÙÍø´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
5.2 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ