VYPR

Teamcity

by Jetbrains

Source repositories

CVEs (277)

  • CVE-2021-25777MedFeb 3, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.

  • CVE-2021-25772MedFeb 3, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.

  • CVE-2020-27629MedNov 16, 2020
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.

  • CVE-2020-15829MedAug 8, 2020
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

  • CVE-2020-7910MedJan 30, 2020
    risk 0.35cvss 5.4epss 0.01

    JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.

  • CVE-2019-18367MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

  • CVE-2019-18366MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.

  • CVE-2019-18363MedOct 31, 2019
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.

  • CVE-2019-12156MedOct 2, 2019
    risk 0.35cvss 5.3epss 0.01

    Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.

  • CVE-2019-12845MedJul 3, 2019
    risk 0.35cvss 5.3epss 0.01

    The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.

  • CVE-2024-56349MedDec 20, 2024
    risk 0.34cvss 5.3epss 0.00

    In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs

  • CVE-2024-47949MedOct 8, 2024
    risk 0.34cvss 4.9epss 0.23

    In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

  • CVE-2024-36375MedMay 29, 2024
    risk 0.34cvss 5.3epss 0.00

    In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

  • CVE-2023-41249MedAug 25, 2023
    risk 0.34cvss 4.6epss 0.53

    In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

  • CVE-2023-34228MedMay 31, 2023
    risk 0.34cvss 5.3epss 0.00

    In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions

  • CVE-2023-34227MedMay 31, 2023
    risk 0.34cvss 5.3epss 0.01

    In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks

  • CVE-2022-48342MedFeb 23, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

  • CVE-2021-37546MedAug 6, 2021
    risk 0.34cvss 5.3epss 0.01

    In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

  • CVE-2024-39879MedJul 1, 2024
    risk 0.33cvss 5.0epss 0.00

    In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

  • CVE-2025-52877MedJun 23, 2025
    risk 0.32cvss 4.8epss 0.17

    In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Page 8 of 14