Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-68267 | Med | 0.42 | 6.5 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token | ||
| CVE-2025-24461 | Med | 0.42 | 6.5 | 0.00 | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint | ||
| CVE-2024-41824 | Med | 0.42 | 6.4 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases | ||
| CVE-2024-36377 | Med | 0.42 | 6.5 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions | ||
| CVE-2024-36376 | Med | 0.42 | 6.5 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions | ||
| CVE-2024-36364 | Med | 0.42 | 6.5 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible | ||
| CVE-2024-36362 | Med | 0.42 | 6.5 | 0.01 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible | ||
| CVE-2024-31134 | Med | 0.42 | 6.5 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled | ||
| CVE-2015-1313 | Med | 0.42 | 6.5 | 0.01 | Jun 29, 2023 | JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request. | ||
| CVE-2022-44624 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters | ||
| CVE-2022-44623 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings | ||
| CVE-2022-24337 | Med | 0.42 | 6.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions. | ||
| CVE-2022-24333 | Med | 0.42 | 6.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible. | ||
| CVE-2020-15828 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions. | ||
| CVE-2020-11689 | Med | 0.42 | 6.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file. | ||
| CVE-2024-56351 | Med | 0.41 | 6.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | ||
| CVE-2026-49375 | Med | 0.40 | 6.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | ||
| CVE-2024-31135 | Med | 0.40 | 6.1 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | ||
| CVE-2022-48343 | Med | 0.40 | 5.4 | 0.59 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. | ||
| CVE-2022-25261 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS. |
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
- risk 0.42cvss 6.4epss 0.00
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
- risk 0.42cvss 6.5epss 0.00
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
- risk 0.42cvss 6.5epss 0.01
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
- risk 0.42cvss 6.5epss 0.01
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
- risk 0.41cvss 6.3epss 0.00
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
- risk 0.40cvss 6.1epss 0.00
In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
- risk 0.40cvss 6.1epss 0.00
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
- risk 0.40cvss 5.4epss 0.59
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
Page 4 of 14