vendor:
TeamCity
by:
Dylan Pindur
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: TeamCity
Affected Version From: TeamCity < 10.0 (42002)
Affected Version To: TeamCity < 10.0 (42002)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 (x64)
2020
TeamCity Agent XML-RPC 10.0 – Remote Code Execution
TeamCity Agents configured to use bidirectional communication allow the execution of commands sent to them via an XML-RPC endpoint. This script requires the following python modules are installed pip install requests.
Mitigation:
Ensure that TeamCity Agents are configured to use unidirectional communication.