Skip to content

Conversation

@frkngksl
Copy link
Contributor

@frkngksl frkngksl commented Oct 9, 2025

Hi @tooryx , @maoning ,

This is the PR that resolves #404

Testbed is: google/security-testbeds#174

@giacomo-doyensec
Copy link
Collaborator

Hello @frkngksl, thanks for this PR.
Can you make the delete_added_user action a cleanup action of create_admin_user?

@frkngksl
Copy link
Contributor Author

Hello @frkngksl, thanks for this PR. Can you make the delete_added_user action a cleanup action of create_admin_user?

Is this a new future right ? I didnt know that 😁

@frkngksl
Copy link
Contributor Author

I guess it's done @giacomo-doyensec

@giacomo-doyensec
Copy link
Collaborator

Thanks for the swift update! Is there a specific reason you put the cleanup action on create_admin_token instead of create_admin_user?

@frkngksl
Copy link
Contributor Author

Hi again @giacomo-doyensec , I thought that that token action is the last operation for the newly created user, that's why I selected it, but considering your comment, the best practice should be adding to the action which creates the user. I updated it correctly. Sorry for the misunderstanding.

@giacomo-doyensec
Copy link
Collaborator

No problem at all @frkngksl, the plugin and relative testbed looks good, let me close this!

@giacomo-doyensec
Copy link
Collaborator

LGTM - Approved
@tooryx , this can be merged along with google/security-testbeds#174.

Reviewer: Giacomo, Doyensec
Plugin: CVE-2024-27198
Drawbacks: None.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PRP: Request CVE-2024-27198 TeamCity Unauthenticated Remote Code Execution

3 participants