cbcvebase.

Jetbrains Teamcity vulnerabilities

276 known vulnerabilities affecting jetbrains/teamcity.

Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9

Vulnerabilities

Page 14 of 14
CVE-2019-12846P4MEDIUMCVSS 4.3fixed in 2018.2.22019-07-03
CVE-2019-12846 [MEDIUM] CVE-2019-12846: A user without the required permissions could gain access to some JetBrains TeamCity settings. The i A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
nvd
CVE-2024-28173P4MEDIUMCVSS 4.3≥ 2023.11, < 2023.11.42024-03-06
CVE-2024-28173 [MEDIUM] CWE-201 CVE-2024-28173: In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type c In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
nvd
CVE-2025-52878P4MEDIUMCVSS 4.3fixed in 2025.03.32025-06-23
CVE-2025-52878 [MEDIUM] CWE-862 CVE-2025-52878: In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permission In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
nvd
CVE-2020-7908P4MEDIUMCVSS 4.3fixed in 2019.1.52020-01-30
CVE-2020-7908 [MEDIUM] CWE-269 CVE-2020-7908: In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages. In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
nvd
CVE-2019-18365P4MEDIUMCVSS 4.3fixed in 2019.1.42019-10-31
CVE-2019-18365 [MEDIUM] CWE-269 CVE-2019-18365: In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages. In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
nvd
CVE-2020-15826P4MEDIUMCVSS 4.3fixed in 2020.12020-08-08
CVE-2020-15826 [MEDIUM] CWE-269 CVE-2020-15826: In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
nvd
CVE-2023-34224P4MEDIUMCVSS 4.8fixed in 2023.052023-05-31
CVE-2023-34224 [MEDIUM] CWE-601 CVE-2023-34224: In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
nvd
CVE-2021-25775P4LOWCVSS 3.8fixed in 2020.2.12021-02-03
CVE-2021-25775 [LOW] CVE-2021-25775: In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any o In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
nvd
CVE-2025-57733P4LOWCVSS 3.8fixed in 2025.07.12025-08-20
CVE-2025-57733 [LOW] CWE-77 CVE-2025-57733: In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email co In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content
nvd
CVE-2025-67739P4LOWCVSS 3.1fixed in 2025.11.22025-12-11
CVE-2025-67739 [LOW] CWE-939 CVE-2025-67739: In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
nvd
CVE-2025-68164P4LOWCVSS 2.7fixed in 2025.112025-12-16
CVE-2025-68164 [LOW] CWE-203 CVE-2025-68164: In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
nvd
CVE-2025-68162P4LOWCVSS 2.7fixed in 2025.112025-12-16
CVE-2025-68162 [LOW] CWE-829 CVE-2025-68162: In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configura In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
nvd
CVE-2021-31906P4LOWCVSS 2.7fixed in 2020.2.22021-05-11
CVE-2021-31906 [LOW] CVE-2021-31906: In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
nvd
CVE-2026-28196P4LOWCVSS 2.3fixed in 2025.11.32026-02-25
CVE-2026-28196 [LOW] CWE-459 CVE-2026-28196: In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on dis In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
nvd
CVE-2021-26309P4LOWCVSS 3.3fixed in 2020.2.2.858992021-05-11
CVE-2021-26309 [LOW] CWE-668 CVE-2021-26309: Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible becaus Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
nvd
CVE-2020-11686P4LOWCVSS 2.7fixed in 2019.1.42020-04-22
CVE-2020-11686 [LOW] CVE-2020-11686: In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity se In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
nvd
Jetbrains Teamcity vulnerabilities | cvebase