Jetbrains Teamcity vulnerabilities
276 known vulnerabilities affecting jetbrains/teamcity.
Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9
Vulnerabilities
Page 14 of 14
CVE-2019-12846P4MEDIUMCVSS 4.3fixed in 2018.2.22019-07-03
CVE-2019-12846 [MEDIUM] CVE-2019-12846: A user without the required permissions could gain access to some JetBrains TeamCity settings. The i
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
nvd
CVE-2024-28173P4MEDIUMCVSS 4.3≥ 2023.11, < 2023.11.42024-03-06
CVE-2024-28173 [MEDIUM] CWE-201 CVE-2024-28173: In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type c
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
nvd
CVE-2025-52878P4MEDIUMCVSS 4.3fixed in 2025.03.32025-06-23
CVE-2025-52878 [MEDIUM] CWE-862 CVE-2025-52878: In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permission
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
nvd
CVE-2020-7908P4MEDIUMCVSS 4.3fixed in 2019.1.52020-01-30
CVE-2020-7908 [MEDIUM] CWE-269 CVE-2020-7908: In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
nvd
CVE-2019-18365P4MEDIUMCVSS 4.3fixed in 2019.1.42019-10-31
CVE-2019-18365 [MEDIUM] CWE-269 CVE-2019-18365: In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
nvd
CVE-2020-15826P4MEDIUMCVSS 4.3fixed in 2020.12020-08-08
CVE-2020-15826 [MEDIUM] CWE-269 CVE-2020-15826: In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
nvd
CVE-2023-34224P4MEDIUMCVSS 4.8fixed in 2023.052023-05-31
CVE-2023-34224 [MEDIUM] CWE-601 CVE-2023-34224: In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
nvd
CVE-2021-25775P4LOWCVSS 3.8fixed in 2020.2.12021-02-03
CVE-2021-25775 [LOW] CVE-2021-25775: In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any o
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
nvd
CVE-2025-57733P4LOWCVSS 3.8fixed in 2025.07.12025-08-20
CVE-2025-57733 [LOW] CWE-77 CVE-2025-57733: In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email co
In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
nvd
CVE-2025-67739P4LOWCVSS 3.1fixed in 2025.11.22025-12-11
CVE-2025-67739 [LOW] CWE-939 CVE-2025-67739: In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
nvd
CVE-2025-68164P4LOWCVSS 2.7fixed in 2025.112025-12-16
CVE-2025-68164 [LOW] CWE-203 CVE-2025-68164: In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
nvd
CVE-2025-68162P4LOWCVSS 2.7fixed in 2025.112025-12-16
CVE-2025-68162 [LOW] CWE-829 CVE-2025-68162: In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configura
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
nvd
CVE-2021-31906P4LOWCVSS 2.7fixed in 2020.2.22021-05-11
CVE-2021-31906 [LOW] CVE-2021-31906: In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
nvd
CVE-2026-28196P4LOWCVSS 2.3fixed in 2025.11.32026-02-25
CVE-2026-28196 [LOW] CWE-459 CVE-2026-28196: In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on dis
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
nvd
CVE-2021-26309P4LOWCVSS 3.3fixed in 2020.2.2.858992021-05-11
CVE-2021-26309 [LOW] CWE-668 CVE-2021-26309: Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible becaus
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
nvd
CVE-2020-11686P4LOWCVSS 2.7fixed in 2019.1.42020-04-22
CVE-2020-11686 [LOW] CVE-2020-11686: In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity se
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
nvd
← Previous14 / 14