Teamcity
by Jetbrains
Source repositories
CVEs (277)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25777 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. | ||
| CVE-2021-25772 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. | ||
| CVE-2020-27629 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts. | ||
| CVE-2020-15829 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs. | ||
| CVE-2020-7910 | Med | 0.35 | 5.4 | 0.01 | Jan 30, 2020 | JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. | ||
| CVE-2019-18367 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions. | ||
| CVE-2019-18366 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission. | ||
| CVE-2019-18363 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances. | ||
| CVE-2019-12156 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293. | ||
| CVE-2019-12845 | Med | 0.35 | 5.3 | 0.01 | Jul 3, 2019 | The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3. | ||
| CVE-2024-56349 | Med | 0.34 | 5.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | ||
| CVE-2024-47949 | Med | 0.34 | 4.9 | 0.23 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | ||
| CVE-2024-36375 | Med | 0.34 | 5.3 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed | ||
| CVE-2023-41249 | Med | 0.34 | 4.6 | 0.53 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | ||
| CVE-2023-34228 | Med | 0.34 | 5.3 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | ||
| CVE-2023-34227 | Med | 0.34 | 5.3 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks | ||
| CVE-2022-48342 | Med | 0.34 | 5.2 | 0.00 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents. | ||
| CVE-2021-37546 | Med | 0.34 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. | ||
| CVE-2024-39879 | Med | 0.33 | 5.0 | 0.00 | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings | ||
| CVE-2025-52877 | Med | 0.32 | 4.8 | 0.17 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible |
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
- risk 0.35cvss 5.4epss 0.01
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
- risk 0.35cvss 5.3epss 0.01
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
- risk 0.35cvss 5.3epss 0.01
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
- risk 0.34cvss 4.9epss 0.23
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
- risk 0.34cvss 4.6epss 0.53
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
- risk 0.34cvss 5.2epss 0.00
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
- risk 0.33cvss 5.0epss 0.00
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
- risk 0.32cvss 4.8epss 0.17
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
Page 8 of 14