Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-28174 | Med | 0.38 | 5.8 | 0.00 | Mar 6, 2024 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | ||
| CVE-2025-59456 | Med | 0.37 | 5.5 | 0.12 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | ||
| CVE-2024-24942 | Med | 0.37 | 5.3 | 0.32 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | ||
| CVE-2025-57733 | Med | 0.36 | 5.5 | 0.00 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content | ||
| CVE-2025-54538 | Med | 0.36 | 5.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command | ||
| CVE-2025-54537 | Med | 0.36 | 5.5 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots | ||
| CVE-2025-52876 | Med | 0.36 | 5.4 | 0.17 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible | ||
| CVE-2024-56354 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | ||
| CVE-2024-56353 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies | ||
| CVE-2024-35301 | Med | 0.36 | 5.5 | 0.00 | May 16, 2024 | In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token | ||
| CVE-2024-31138 | Med | 0.36 | 4.6 | 0.74 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | ||
| CVE-2025-68268 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page | ||
| CVE-2025-68166 | Med | 0.35 | 5.4 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab | ||
| CVE-2025-68165 | Med | 0.35 | 5.4 | 0.04 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup | ||
| CVE-2025-54536 | Med | 0.35 | 5.4 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint | ||
| CVE-2025-54528 | Med | 0.35 | 5.4 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | ||
| CVE-2025-52875 | Med | 0.35 | 5.4 | 0.01 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible | ||
| CVE-2024-36366 | Med | 0.35 | 5.4 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations | ||
| CVE-2024-35302 | Med | 0.35 | 5.4 | 0.00 | May 16, 2024 | In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible | ||
| CVE-2024-24938 | Med | 0.35 | 5.3 | 0.01 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation |
- risk 0.38cvss 5.8epss 0.00
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
- risk 0.37cvss 5.5epss 0.12
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
- risk 0.37cvss 5.3epss 0.32
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
- risk 0.36cvss 5.4epss 0.17
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
- risk 0.36cvss 4.6epss 0.74
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
- risk 0.35cvss 5.4epss 0.04
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
- risk 0.35cvss 5.4epss 0.01
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
Page 6 of 14