VendorsJetBrainsteamcityany version
Vulnerabilities

JetBrains TeamCity any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

265CVEs
CVE-2020-27629
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
Published 2020-11-16 · Modified
5.3EPSS 0.009
CVE-2019-12845
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
Published 2019-07-03 · Modified
5.3EPSS 0.009
CVE-2019-18363
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
Published 2019-10-31 · Modified
5.3EPSS 0.009
CVE-2021-31907
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
Published 2021-05-11 · Modified
5.3EPSS 0.009
CVE-2021-43194
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
Published 2021-11-09 · Modified
5.3EPSS 0.008
CVE-2021-25778
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
Published 2021-02-03 · Modified
5.3EPSS 0.008
CVE-2024-24938
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
Published 2024-02-06 · Modified
5.3EPSS 0.007
CVE-2022-24336
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
Published 2022-02-25 · Modified
5.3EPSS 0.007
CVE-2019-18367
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
Published 2019-10-31 · Modified
5.3EPSS 0.007
CVE-2021-25777
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
Published 2021-02-03 · Modified
5.3EPSS 0.007
CVE-2021-43195
In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
Published 2021-11-09 · Modified
5.3EPSS 0.007
CVE-2021-43201
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
Published 2021-11-09 · Modified
5.3EPSS 0.007
CVE-2021-37547
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
Published 2021-08-06 · Modified
5.3EPSS 0.007
CVE-2022-24334
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
Published 2022-02-25 · Modified
5.3EPSS 0.007
CVE-2021-43199
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
Published 2021-11-09 · Modified
5.3EPSS 0.007
CVE-2022-24332
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
Published 2022-02-25 · Modified
5.3EPSS 0.007
CVE-2021-37546
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
Published 2021-08-06 · Modified
5.3EPSS 0.005
CVE-2022-46830
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
Published 2022-12-08 · Modified
5.3EPSS 0.005
CVE-2022-44622
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
Published 2022-11-03 · Modified
5.3EPSS 0.005
CVE-2022-38133
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
Published 2022-08-10 · Modified
5.3EPSS 0.004
CVE-2022-44646
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
Published 2022-11-03 · Modified
5.3EPSS 0.004
CVE-2022-40979
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
Published 2022-09-23 · Modified
5.3EPSS 0.004
CVE-2024-36375
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
Published 2024-05-29 · Analyzed
5.3EPSS 0.003
CVE-2024-24936
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
Published 2024-02-06 · Modified
5.3EPSS 0.003
CVE-2024-39879
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
Published 2024-07-01 · Modified
5.3EPSS 0.003
CVE-2024-39878
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
Published 2024-07-01 · Modified
5.3EPSS 0.003
CVE-2024-56349
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
Published 2024-12-20 · Analyzed
5.3EPSS 0.003
CVE-2025-67740
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
Published 2025-12-11 · Analyzed
5.3EPSS 0.002
CVE-2014-10002
Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors.
Published 2015-01-13 · Modified
5.0EPSS 0.012
CVE-2020-11938
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
Published 2020-04-22 · Modified
4.9EPSS 0.009
CVE-2022-29928
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
Published 2022-05-12 · Modified
4.9EPSS 0.005
CVE-2024-31140
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
Published 2024-03-28 · Analyzed
4.9EPSS 0.004
CVE-2025-52877
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
Published 2025-06-23 · Analyzed
4.8EPSS 0.367
CVE-2025-52879
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
Published 2025-06-23 · Analyzed
4.8EPSS 0.012
CVE-2025-54534
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
Published 2025-07-28 · Analyzed
4.8EPSS 0.008
CVE-2023-34224
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
Published 2023-05-31 · Modified
4.8EPSS 0.003
CVE-2024-41826
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
Published 2024-07-22 · Modified
4.8EPSS 0.003
CVE-2026-49381
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
Published 2026-05-29 · Analyzed
4.8EPSS 0.003
CVE-2025-68163
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
Published 2025-12-16 · Analyzed
4.8EPSS 0.002
CVE-2014-10036
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
Published 2015-01-13 · Modified
4.3EPSS 0.019
← Prev6 / 7Next →