Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-31910 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. | ||
| CVE-2021-26310 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible. | ||
| CVE-2021-25776 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. | ||
| CVE-2020-35667 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials. | ||
| CVE-2020-11688 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. | ||
| CVE-2020-11687 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. | ||
| CVE-2020-7909 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. | ||
| CVE-2019-15042 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1. | ||
| CVE-2019-15038 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1. | ||
| CVE-2019-12841 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2019 | Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2024-41827 | Hig | 0.48 | 7.4 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | ||
| CVE-2024-31136 | Hig | 0.48 | 7.4 | 0.01 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | ||
| CVE-2026-49373 | Hig | 0.47 | 7.1 | 0.13 | May 29, 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | ||
| CVE-2019-15036 | Hig | 0.47 | 7.2 | 0.02 | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1. | ||
| CVE-2026-49371 | Hig | 0.46 | 7.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | ||
| CVE-2024-36365 | Med | 0.44 | 6.8 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent | ||
| CVE-2024-31137 | Med | 0.44 | 6.8 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | ||
| CVE-2022-46831 | Med | 0.43 | 6.6 | 0.00 | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators. | ||
| CVE-2026-49379 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | ||
| CVE-2026-49376 | Med | 0.42 | 6.5 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
- risk 0.49cvss 7.5epss 0.02
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
- risk 0.49cvss 7.5epss 0.01
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
- risk 0.49cvss 7.5epss 0.01
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
- risk 0.48cvss 7.4epss 0.00
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
- risk 0.48cvss 7.4epss 0.01
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
- risk 0.47cvss 7.1epss 0.13
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
- risk 0.47cvss 7.2epss 0.02
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
- risk 0.46cvss 7.1epss 0.00
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
- risk 0.44cvss 6.8epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
- risk 0.44cvss 6.8epss 0.00
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
- risk 0.43cvss 6.6epss 0.00
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Page 3 of 14