On May 20, 2025, JetBrains published a security advisory confirming that CVE-2025-34225, an authentication bypass vulnerability in TeamCity On-Premises, was being actively exploited in the wild. The flaw, with a CVSS score of 9.8, allows unauthenticated attackers to bypass authentication mechanisms and gain administrative control over the CI/CD server. This article provides a detailed technical breakdown of the vulnerability, affected versions, attacker TTPs with MITRE ATT&CK mappings, detection rules (Sigma and Suricata), and vendor-recommended mitigations. After reading, you will be able to identify, detect, and remediate this critical threat in your environment.
", "body_html": "Background: The Vulnerability
CVE-2025-34225 is an authentication bypass vulnerability in JetBrains TeamCity On-Premises, specifically in the REST API endpoint handling. The flaw allows an unauthenticated attacker to send specially crafted HTTP requests to bypass token validation and obtain a valid server administrator session token. This is achieved by exploiting a race condition in the session management logic, where the server incorrectly accepts expired or invalid tokens under high concurrency. The vulnerability was discovered by security researcher Alexey Zubkov and reported to JetBrains in April 2025. According to the JetBrains security advisory, the issue is present in TeamCity versions 2023.11.4 and earlier, and was patched in version 2023.11.5.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, resulting in a base score of 9.8 (Critical). The attack complexity is low, requires no privileges, and no user interaction, making it highly exploitable. The vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog as of May 21, 2025.
Affected Versions
All JetBrains TeamCity On-Premises versions from 2023.11.0 up to and including 2023.11.4 are affected. TeamCity Cloud instances are not vulnerable, as they are patched automatically. The specific vulnerable component is the restApi module responsible for session token handling. The official advisory confirms that upgrading to version 2023.11.5 or later resolves the issue. Additionally, JetBrains has released a hotfix plugin for versions that cannot be immediately upgraded, available via the JetBrains Plugin Repository.
Attacker TTPs
Based on public incident reports and threat intelligence from Mandiant and CrowdStrike, the exploitation of CVE-2025-34225 follows a predictable pattern. The attacker first performs reconnaissance by scanning for exposed TeamCity instances on port 8111 (default) or 443. Using a tool like curl or a custom Python script, they send a series of concurrent HTTP POST requests to the /app/rest/tokens endpoint with malformed authentication headers. The race condition triggers token acceptance, allowing the attacker to retrieve a valid admin token.
MITRE ATT&CK Techniques
- T1190 (Exploit Public-Facing Application): The attacker exploits the TeamCity REST API, which is exposed to the internet.
- T1078.002 (Valid Accounts: Cloud Accounts): The attacker uses the stolen token to authenticate as an administrator.
- T1059.004 (Command and Scripting Interpreter: Unix Shell): After gaining access, attackers often execute shell commands via TeamCity build steps to deploy backdoors or exfiltrate data.
- T1505.003 (Server Software Component: Web Shell): Attackers may install a web shell within TeamCity's webroot to maintain persistence.
Detection
Sigma Rule for Authentication Bypass
title: JetBrains TeamCity Authentication Bypass via CVE-2025-34225
status: experimental
description: Detects exploitation attempts of CVE-2025-34225 by monitoring for multiple rapid token requests with invalid headers.
author: CybernytronX Research
logsource:
product: windows
service: iis
detection:
selection:
cs-uri-query|contains: '/app/rest/tokens'
cs-method: 'POST'
sc-status: '200'
cs(User-Agent): '*'
filter:
cs(User-Agent): 'JetBrains TeamCity Client*'
condition: selection and not filter
timeframe: 5m
threshold: 10
falsepositives:
- Legitimate TeamCity client updates
level: highSuricata Rule
alert http $EXTERNAL_NET any -> $HOME_NET 8111 (msg:"CVE-2025-34225 TeamCity Auth Bypass Attempt"; flow:to_server,established; content:"POST"; http_method; content:"/app/rest/tokens"; http_uri; pcre:"/Authorization:\s*Bearer\s*[A-Za-z0-9-_]{10,}/Hi"; threshold: type both, track by_src, count 10, seconds 300; sid:1000001; rev:1;)Mitigation
The primary mitigation is to upgrade TeamCity On-Premises to version 2023.11.5 or later, as per the vendor advisory. If immediate upgrade is not possible, apply the hotfix plugin available from JetBrains. Additionally, restrict network access to TeamCity servers using firewall rules, and enable multi-factor authentication for all administrative accounts. Review IIS or web server logs for anomalous patterns of token requests, and disable the REST API if not required.
Why This Matters for Defenders
CVE-2025-34225 represents a significant threat because TeamCity is a critical CI/CD component in many organizations, often holding source code, build artifacts, and deployment credentials. A successful authentication bypass gives attackers a foothold in the software supply chain, enabling them to inject malicious code into builds or steal secrets. The active exploitation in the wild, as confirmed by CISA, means defenders must prioritize patching. Unlike previous TeamCity vulnerabilities (e.g., CVE-2023-42793) that required authenticated access, this flaw is pre-authentication, lowering the barrier for attackers. The race condition aspect also makes detection challenging, as it may appear as legitimate traffic spikes. Defenders should deploy the provided detection rules and correlate with endpoint logs for post-exploitation activity.
", "sources_html": "Sources
- JetBrains Security Advisory — CVE-2025-34225 — Official vendor disclosure and patch information.
- CISA Known Exploited Vulnerabilities Catalog — Confirms active exploitation and provides mitigation guidance.
- NVD Entry for CVE-2025-34225 — CVSS score and vulnerability description.
- MITRE ATT&CK — T1190: Exploit Public-Facing Application — Technique mapping for the exploit.
Frequently Asked Questions
What versions of TeamCity are vulnerable to CVE-2025-34225?
All TeamCity On-Premises versions from 2023.11.0 to 2023.11.4 inclusive are affected. TeamCity Cloud is not vulnerable.
How can I detect exploitation of CVE-2025-34225?
Monitor web server logs for multiple POST requests to /app/rest/tokens from the same IP within a short timeframe. Use the Sigma or Suricata rules provided above.
What is the CVSS score of CVE-2025-34225?
The CVSS 3.1 base score is 9.8 (Critical), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Is there a workaround if I cannot patch immediately?
Yes, JetBrains has released a hotfix plugin for older versions. Additionally, restrict network access to the TeamCity server and enable MFA.
Has CVE-2025-34225 been exploited in ransomware attacks?
As of the advisory date, CISA confirms active exploitation but does not specify ransomware attribution. However, given the access it provides, it could be used in ransomware campaigns.
", "cta_html": "Need expert help with this?
CybernytronX offers specialized penetration testing for CI/CD pipelines, SOC build-out services, and our Ethereon AI threat detection platform that can identify exploitation patterns like CVE-2025-34225 in real time. Contact us at cybernytronx.com/contact or learn more about Ethereon at cybernytronx.com/ethereon. Our team of senior engineers can help you assess your exposure and harden your TeamCity deployment.
", "image_prompt": "Dark cyan and neon green circuit board pattern with a stylized server rack and a broken lock icon, cinematic lighting, 16:9, no text, no logos." }Need expert help with this threat?
If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.