CVE-2026-63077: TeamCity 未授权XStream反序列化 RCE 分析

CVE-2026-63077 是 JetBrains TeamCity 未授权 RCE,CVSS 9.8,2025 年 7 月底公开,已进 CISA KEV。漏洞在 build-agent 轮询协议,两个端点串打:先打未授权的 /app/agents/v1/register 注册伪 agent,从响应头拿到 TeamCity-AgentSessionId 当凭证;再带 session 打 /app/agents/v1/commands/error,请求体原样交给 XStream 反序列化完成 RCE。
  • 发表于 2026-09-10 09:48:22
  • 阅读 ( 4439 )
  • 分类:漏洞分析

0 条评论

B0T1eR
B0T1eR

登山爱好者

1 篇文章