Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24936 | Med | 0.28 | 4.3 | 0.00 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed | ||
| CVE-2023-50870 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2023 | In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible | ||
| CVE-2023-39174 | Med | 0.28 | 4.3 | 0.02 | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers | ||
| CVE-2023-38067 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log | ||
| CVE-2023-38064 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log | ||
| CVE-2023-38062 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations | ||
| CVE-2023-34223 | Med | 0.28 | 4.3 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | ||
| CVE-2023-34219 | Med | 0.28 | 4.3 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API | ||
| CVE-2021-25774 | Med | 0.28 | 4.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. | ||
| CVE-2020-27628 | Med | 0.28 | 4.3 | 0.01 | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records. | ||
| CVE-2020-15826 | Med | 0.28 | 4.3 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. | ||
| CVE-2020-7908 | Med | 0.28 | 4.3 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages. | ||
| CVE-2019-18365 | Med | 0.28 | 4.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages. | ||
| CVE-2019-12846 | Med | 0.28 | 4.3 | 0.01 | Jul 3, 2019 | A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2025-59455 | Med | 0.27 | 4.2 | 0.00 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition | ||
| CVE-2024-39878 | Med | 0.27 | 4.1 | 0.00 | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection | ||
| CVE-2024-31140 | Med | 0.27 | 4.1 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools | ||
| CVE-2024-29880 | Med | 0.27 | 4.2 | 0.00 | Mar 21, 2024 | In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | ||
| CVE-2022-46830 | Med | 0.27 | 4.1 | 0.00 | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. | ||
| CVE-2022-36321 | Med | 0.27 | 4.1 | 0.02 | Jul 20, 2022 | In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases |
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
- risk 0.28cvss 4.3epss 0.02
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
- risk 0.28cvss 4.3epss 0.01
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
- risk 0.27cvss 4.2epss 0.00
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
- risk 0.27cvss 4.1epss 0.00
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
- risk 0.27cvss 4.1epss 0.00
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
- risk 0.27cvss 4.2epss 0.00
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
- risk 0.27cvss 4.1epss 0.00
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
- risk 0.27cvss 4.1epss 0.02
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
Page 12 of 14