Name:JetBrains TeamCity Limited Auth Bypass Suricata CVE-2024-27199 id:a1e68dcd-2e24-4434-bd0e-b3d4de139d58 version:4 date:2024-11-15 author:Michael Haag, Splunk status:production type:TTP Description:The following analytic identifies attempts to exploit CVE-2024-27199, a critical vulnerability in JetBrains TeamCity web server, allowing unauthenticated access to specific endpoints. It detects unusual access patterns to vulnerable paths such as /res/, /update/, and /.well-known/acme-challenge/ by monitoring HTTP traffic logs via Suricata. This activity is significant as it could indicate an attacker bypassing authentication to access or modify system settings. If confirmed malicious, this could lead to unauthorized changes, disclosure of sensitive information, or uploading of malicious certificates, severely compromising the server's security. Data_source: