Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24338 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. | ||
| CVE-2022-24330 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. | ||
| CVE-2021-43197 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. | ||
| CVE-2021-37542 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.3, XSS was possible. | ||
| CVE-2021-31911 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. | ||
| CVE-2021-31904 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page. | ||
| CVE-2021-25773 | Med | 0.40 | 6.1 | 0.01 | Feb 3, 2021 | JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. | ||
| CVE-2020-27627 | Med | 0.40 | 6.1 | 0.01 | Nov 16, 2020 | JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. | ||
| CVE-2020-15831 | Med | 0.40 | 6.1 | 0.01 | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. | ||
| CVE-2020-15830 | Med | 0.40 | 6.1 | 0.01 | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI. | ||
| CVE-2020-7911 | Med | 0.40 | 6.1 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. | ||
| CVE-2019-15037 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1. | ||
| CVE-2019-15848 | Med | 0.40 | 6.1 | 0.01 | Sep 5, 2019 | JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user. | ||
| CVE-2019-12844 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3. | ||
| CVE-2019-12843 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3. | ||
| CVE-2019-12842 | Med | 0.40 | 6.1 | 0.01 | Jul 3, 2019 | A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2025-54535 | Med | 0.38 | 5.8 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms | ||
| CVE-2024-56356 | Med | 0.38 | 5.9 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | ||
| CVE-2024-36378 | Med | 0.38 | 5.9 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens | ||
| CVE-2024-31139 | Med | 0.38 | 5.9 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector |
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.3, XSS was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
- risk 0.40cvss 6.1epss 0.01
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
- risk 0.40cvss 6.1epss 0.01
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
- risk 0.40cvss 6.1epss 0.01
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
- risk 0.40cvss 6.1epss 0.01
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
- risk 0.40cvss 6.1epss 0.01
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
- risk 0.38cvss 5.8epss 0.00
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
Page 5 of 14