cbcvebase.

Jetbrains Teamcity vulnerabilities

276 known vulnerabilities affecting jetbrains/teamcity.

Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9

Vulnerabilities

Page 12 of 14
CVE-2022-44646P4MEDIUMCVSS 5.3fixed in 2022.10≥ 2022.10, < 2022.102022-11-03
CVE-2022-44646 [MEDIUM] CWE-223 CVE-2022-44646: In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settin In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
nvd
CVE-2019-15035P4MEDIUMCVSS 4.9v2018.2.42019-10-01
CVE-2019-15035 [MEDIUM] CVE-2019-15035: An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get a An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
nvd
CVE-2020-11938P4MEDIUMCVSS 4.9≥ 2018.2, ≤ 2019.2.12020-04-22
CVE-2020-11938 [MEDIUM] CVE-2020-11938: In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled pas In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
nvd
CVE-2022-46831P4MEDIUMCVSS 4.9≥ 2022.10, ≤ 2022.10.1≥ 2022.10, < 2022.10.12022-12-08
CVE-2022-46831 [MEDIUM] CWE-453 CVE-2022-46831: In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
nvd
CVE-2024-56354P4MEDIUMCVSS 4.9fixed in 2024.122024-12-20
CVE-2024-56354 [MEDIUM] CWE-522 CVE-2024-56354: In JetBrains TeamCity before 2024.12 password field value were accessible to users with view setting In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
nvd
CVE-2026-49378P4MEDIUMCVSS 4.3fixed in 2026.12026-05-29
CVE-2026-49378 [MEDIUM] CWE-862 CVE-2026-49378: In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
nvd
CVE-2023-34226P4MEDIUMCVSS 6.1fixed in 2023.052023-05-31
CVE-2023-34226 [MEDIUM] CWE-79 CVE-2023-34226: In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
nvd
CVE-2021-31911P4MEDIUMCVSS 6.1fixed in 2020.2.32021-05-11
CVE-2021-31911 [MEDIUM] CWE-79 CVE-2021-31911: In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
nvd
CVE-2021-31904P4MEDIUMCVSS 6.1fixed in 2020.2.22021-05-11
CVE-2021-31904 [MEDIUM] CWE-79 CVE-2021-31904: In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page. In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
nvd
CVE-2020-15831P4MEDIUMCVSS 6.1fixed in 2019.2.32020-08-08
CVE-2020-15831 [MEDIUM] CWE-79 CVE-2020-15831: JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
nvd
CVE-2021-25773P4MEDIUMCVSS 6.1fixed in 2020.22021-02-03
CVE-2021-25773 [MEDIUM] CWE-79 CVE-2021-25773: JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
nvd
CVE-2022-24338P4MEDIUMCVSS 6.1fixed in 2021.2.12022-02-25
CVE-2022-24338 [MEDIUM] CWE-79 CVE-2022-24338: JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
nvd
CVE-2022-25261P4MEDIUMCVSS 6.1fixed in 2021.2.22022-02-25
CVE-2022-25261 [MEDIUM] CWE-79 CVE-2022-25261: JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS. JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
nvd
CVE-2021-43197P4MEDIUMCVSS 6.1fixed in 2021.1.22021-11-09
CVE-2021-43197 [MEDIUM] CWE-79 CVE-2021-43197: In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
nvd
CVE-2022-29929P4MEDIUMCVSS 6.1fixed in 2022.04≥ 2022.04, < 2022.042022-05-12
CVE-2022-29929 [MEDIUM] CWE-79 CVE-2022-29929: In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
nvd
CVE-2019-18367P4MEDIUMCVSS 5.3fixed in 2019.1.22019-10-31
CVE-2019-18367 [MEDIUM] CWE-276 CVE-2019-18367: In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user with In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
nvd
CVE-2021-25777P4MEDIUMCVSS 5.3fixed in 2020.2.12021-02-03
CVE-2021-25777 [MEDIUM] CWE-863 CVE-2021-25777: In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
nvd
CVE-2024-43808P4MEDIUMCVSS 5.4fixed in 2024.07.12024-08-16
CVE-2024-43808 [MEDIUM] CWE-79 CVE-2024-43808: In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
nvd
CVE-2026-28195P4MEDIUMCVSS 4.3fixed in 2025.11.32026-02-25
CVE-2026-28195 [MEDIUM] CWE-862 CVE-2026-28195: In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add param In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
nvd
CVE-2023-38066P4MEDIUMCVSS 6.1fixed in 2023.05.12023-07-12
CVE-2023-38066 [MEDIUM] CWE-79 CVE-2023-38066: In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during arti In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
nvd
Jetbrains Teamcity vulnerabilities | cvebase