VendorsJetBrainsteamcityany version
Vulnerabilities

JetBrains TeamCity any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

265CVEs
CVE-2024-56356
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
Published 2024-12-20 · Analyzed
7.1EPSS 0.002
CVE-2024-31137
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
Published 2024-03-28 · Modified
6.8EPSS 0.004
CVE-2022-46831
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
Published 2022-12-08 · Modified
6.6EPSS 0.005
CVE-2022-36321
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
Published 2022-07-20 · Modified
6.5EPSS 0.018
CVE-2023-38062
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
Published 2023-07-12 · Modified
6.5EPSS 0.014
CVE-2020-15828
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
Published 2020-08-08 · Modified
6.5EPSS 0.011
CVE-2025-46432
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
Published 2025-04-25 · Analyzed
6.5EPSS 0.010
CVE-2025-31139
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
Published 2025-03-27 · Analyzed
6.5EPSS 0.010
CVE-2025-57734
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
Published 2025-08-20 · Analyzed
6.5EPSS 0.008
CVE-2022-24333
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
Published 2022-02-25 · Modified
6.5EPSS 0.007
CVE-2022-24337
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.
Published 2022-02-25 · Modified
6.5EPSS 0.007
CVE-2020-11689
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
Published 2020-04-22 · Modified
6.5EPSS 0.006
CVE-2015-1313
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.
Published 2023-06-29 · Modified
6.5EPSS 0.006
CVE-2024-36362
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
Published 2024-05-29 · Analyzed
6.5EPSS 0.005
CVE-2023-38064
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
Published 2023-07-12 · Modified
6.5EPSS 0.005
CVE-2023-38067
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
Published 2023-07-12 · Modified
6.5EPSS 0.005
CVE-2024-31134
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
Published 2024-03-28 · Analyzed
6.5EPSS 0.004
CVE-2023-34228
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
Published 2023-05-31 · Modified
6.5EPSS 0.004
CVE-2026-49379
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
Published 2026-05-29 · Analyzed
6.5EPSS 0.003
CVE-2024-36364
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
Published 2024-05-29 · Analyzed
6.5EPSS 0.003
CVE-2024-56353
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
Published 2024-12-20 · Analyzed
6.5EPSS 0.003
CVE-2024-47161
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
Published 2024-10-08 · Analyzed
6.5EPSS 0.003
CVE-2024-41824
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
Published 2024-07-22 · Modified
6.5EPSS 0.003
CVE-2026-49376
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Published 2026-05-29 · Analyzed
6.5EPSS 0.003
CVE-2024-41828
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
Published 2024-07-22 · Modified
6.5EPSS 0.003
CVE-2025-68267
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
Published 2025-12-16 · Analyzed
6.5EPSS 0.002
CVE-2025-46618
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Published 2025-04-25 · Analyzed
6.1EPSS 0.630
CVE-2022-48343
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
Published 2023-02-23 · Modified
6.1EPSS 0.595
CVE-2023-41249
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
Published 2023-08-25 · Modified
6.1EPSS 0.555
CVE-2025-31140
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
Published 2025-03-27 · Analyzed
6.1EPSS 0.280
CVE-2025-68165
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
Published 2025-12-16 · Analyzed
6.1EPSS 0.042
CVE-2025-24459
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
Published 2025-01-21 · Analyzed
6.1EPSS 0.028
CVE-2022-29927
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
Published 2022-05-12 · Modified
6.1EPSS 0.015
CVE-2023-38066
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
Published 2023-07-12 · Modified
6.1EPSS 0.010
CVE-2023-34222
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
Published 2023-05-31 · Modified
6.1EPSS 0.010
CVE-2023-34226
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
Published 2023-05-31 · Modified
6.1EPSS 0.010
CVE-2023-39175
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
Published 2023-07-25 · Modified
6.1EPSS 0.010
CVE-2019-12844
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
Published 2019-07-03 · Modified
6.1EPSS 0.008
CVE-2019-12842
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
Published 2019-07-03 · Modified
6.1EPSS 0.008
CVE-2019-12843
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
Published 2019-07-03 · Modified
6.1EPSS 0.008
← Prev3 / 7Next →