Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27198 | Cri | 0.93 | 9.8 | 1.00 | KEV | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| CVE-2023-42793 | Cri | 0.93 | 9.8 | 1.00 | KEV | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | |
| CVE-2026-63077 | Cri | 0.76 | 9.8 | 0.11 | KEV | Jul 27, 2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | |
| CVE-2024-27199 | Hig | 0.73 | 7.3 | 1.00 | KEV | Mar 4, 2024 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| CVE-2024-23917 | Cri | 0.68 | 9.8 | 0.54 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible | ||
| CVE-2019-15039 | Cri | 0.68 | 9.8 | 0.13 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. | ||
| CVE-2022-25263 | Cri | 0.64 | 9.8 | 0.02 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. | ||
| CVE-2022-24340 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. | ||
| CVE-2022-24331 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. | ||
| CVE-2021-43202 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2021 | In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. | ||
| CVE-2021-43200 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. | ||
| CVE-2021-43193 | Cri | 0.64 | 9.8 | 0.02 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. | ||
| CVE-2021-37544 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. | ||
| CVE-2021-31915 | Cri | 0.64 | 9.8 | 0.03 | May 11, 2021 | In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. | ||
| CVE-2021-31914 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2021 | In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | ||
| CVE-2021-31909 | Cri | 0.64 | 9.8 | 0.03 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. | ||
| CVE-2019-18364 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. | ||
| CVE-2019-12157 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2019 | In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. | ||
| CVE-2023-34218 | Cri | 0.59 | 9.1 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | ||
| CVE-2026-65906 | Hig | 0.57 | 8.8 | 0.00 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible |
- risk 0.93cvss 9.8epss 1.00
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- risk 0.93cvss 9.8epss 1.00
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- risk 0.76cvss 9.8epss 0.11
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- risk 0.73cvss 7.3epss 1.00
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- risk 0.68cvss 9.8epss 0.54
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
- risk 0.68cvss 9.8epss 0.13
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
- risk 0.64cvss 9.8epss 0.02
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
- risk 0.64cvss 9.8epss 0.02
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
- risk 0.64cvss 9.8epss 0.02
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
- risk 0.64cvss 9.8epss 0.03
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
- risk 0.64cvss 9.8epss 0.02
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
- risk 0.59cvss 9.1epss 0.01
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
- risk 0.57cvss 8.8epss 0.00
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Page 1 of 14