Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-68164 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test | ||
| CVE-2025-68162 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration | ||
| CVE-2025-67740 | Low | 0.18 | 2.7 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata | ||
| CVE-2025-31141 | Low | 0.18 | 2.7 | 0.00 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page | ||
| CVE-2022-44622 | Low | 0.18 | 2.7 | 0.00 | Nov 3, 2022 | In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive | ||
| CVE-2021-31906 | Low | 0.18 | 2.7 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file. | ||
| CVE-2020-11686 | Low | 0.18 | 2.7 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings. | ||
| CVE-2024-41828 | Low | 0.17 | 2.6 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time | ||
| CVE-2026-28196 | Low | 0.15 | 2.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | ||
| CVE-2022-44646 | Low | 0.14 | 2.2 | 0.00 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings | ||
| CVE-2026-65907 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | ||
| CVE-2026-59796 | Hig | 0.00 | 8.1 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | ||
| CVE-2026-59795 | Hig | 0.00 | 8.1 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | ||
| CVE-2026-59794 | Hig | 0.00 | 7.3 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | ||
| CVE-2026-59793 | Hig | 0.00 | 8.8 | 0.00 | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | ||
| CVE-2014-10036 | 0.00 | — | 0.02 | Jan 13, 2015 | Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html. | |||
| CVE-2014-10002 | 0.00 | — | 0.01 | Jan 13, 2015 | Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors. |
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
- risk 0.18cvss 2.7epss 0.01
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
- risk 0.18cvss 2.7epss 0.01
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
- risk 0.17cvss 2.6epss 0.00
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
- risk 0.15cvss 2.3epss 0.00
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
- risk 0.14cvss 2.2epss 0.00
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
- risk 0.00cvss 9.1epss 0.00
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- risk 0.00cvss 8.1epss 0.00
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
- risk 0.00cvss 8.1epss 0.00
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
- risk 0.00cvss 7.3epss 0.00
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
- risk 0.00cvss 8.8epss 0.00
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
- CVE-2014-10036Jan 13, 2015risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
- CVE-2014-10002Jan 13, 2015risk 0.00cvss —epss 0.01
Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors.
Page 14 of 14