Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48426 | Med | 0.30 | 4.6 | 0.01 | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible | ||
| CVE-2022-29927 | Med | 0.30 | 4.6 | 0.01 | May 12, 2022 | In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible | ||
| CVE-2022-40979 | Med | 0.29 | 4.4 | 0.00 | Sep 23, 2022 | In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable | ||
| CVE-2022-29928 | Med | 0.29 | 4.4 | 0.00 | May 12, 2022 | In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible | ||
| CVE-2026-49378 | Med | 0.28 | 4.3 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | ||
| CVE-2026-49377 | Med | 0.28 | 4.3 | 0.01 | May 29, 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | ||
| CVE-2026-28195 | Med | 0.28 | 4.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | ||
| CVE-2026-28194 | Med | 0.28 | 4.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow | ||
| CVE-2025-57734 | Med | 0.28 | 4.3 | 0.01 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files | ||
| CVE-2025-54533 | Med | 0.28 | 4.3 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration | ||
| CVE-2025-54532 | Med | 0.28 | 4.3 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | ||
| CVE-2025-52878 | Med | 0.28 | 4.3 | 0.00 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions | ||
| CVE-2025-47854 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page | ||
| CVE-2025-46432 | Med | 0.28 | 4.3 | 0.01 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | ||
| CVE-2025-31139 | Med | 0.28 | 4.3 | 0.01 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log | ||
| CVE-2025-24460 | Med | 0.28 | 4.3 | 0.00 | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool | ||
| CVE-2024-56350 | Med | 0.28 | 4.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | ||
| CVE-2024-56348 | Med | 0.28 | 4.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | ||
| CVE-2024-47161 | Med | 0.28 | 4.3 | 0.00 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API | ||
| CVE-2024-28173 | Med | 0.28 | 4.3 | 0.01 | Mar 6, 2024 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed |
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
- risk 0.30cvss 4.6epss 0.01
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
- risk 0.29cvss 4.4epss 0.00
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
- risk 0.29cvss 4.4epss 0.00
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
Page 11 of 14