cbcvebase.

Jetbrains Teamcity vulnerabilities

276 known vulnerabilities affecting jetbrains/teamcity.

Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9

Vulnerabilities

Page 2 of 14
CVE-2025-46433P3CRITICALCVSS 9.8fixed in 2025.03.12025-04-25
CVE-2025-46433 [CRITICAL] CWE-23 CVE-2025-46433: In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possi In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
nvd
CVE-2025-54531P3CRITICALCVSS 9.4fixed in 2025.072025-07-28
CVE-2025-54531 [CRITICAL] CWE-23 CVE-2025-54531: In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
nvd
CVE-2024-31138P3MEDIUMCVSS 5.4fixed in 2024.032024-03-28
CVE-2024-31138 [MEDIUM] CWE-79 CVE-2024-31138: In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
nvd
CVE-2019-12157P3CRITICALCVSS 9.8fixed in 2018.2.52019-10-02
CVE-2019-12157 [CRITICAL] CWE-20 CVE-2019-12157: In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC comm In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
nvd
CVE-2023-39173P3HIGHCVSS 8.8fixed in 2023.05.22023-07-25
CVE-2023-39173 [HIGH] CWE-266 CVE-2023-39173: In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full a In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
nvd
CVE-2024-56351P3HIGHCVSS 8.8fixed in 2024.122024-12-20
CVE-2024-56351 [HIGH] CWE-613 CVE-2024-56351: In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
nvd
CVE-2022-48428P3MEDIUMCVSS 5.4fixed in 2022.10.32023-03-27
CVE-2022-48428 [MEDIUM] CWE-79 CVE-2022-48428: In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
nvd
CVE-2022-48343P3MEDIUMCVSS 6.1fixed in 2022.10.22023-02-23
CVE-2022-48343 [MEDIUM] CWE-79 CVE-2022-48343: In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
nvd
CVE-2023-34225P3MEDIUMCVSS 5.4fixed in 2023.052023-05-31
CVE-2023-34225 [MEDIUM] CWE-79 CVE-2023-34225: In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
nvd
CVE-2024-41827P3CRITICALCVSS 9.8fixed in 2024.072024-07-22
CVE-2024-41827 [CRITICAL] CWE-613 CVE-2024-41827: In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirati In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
nvd
CVE-2023-34220P3MEDIUMCVSS 5.4fixed in 2023.052023-05-31
CVE-2023-34220 [MEDIUM] CWE-79 CVE-2023-34220: In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
nvd
CVE-2025-67742P3HIGHCVSS 7.5fixed in 2025.112025-12-11
CVE-2025-67742 [HIGH] CWE-22 CVE-2025-67742: In JetBrains TeamCity before 2025.11 path traversal was possible via file upload In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
nvd
CVE-2023-34218P3CRITICALCVSS 9.8fixed in 2023.052023-05-31
CVE-2023-34218 [CRITICAL] CWE-863 CVE-2023-34218: In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions w In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
nvd
CVE-2023-41249P3MEDIUMCVSS 6.1fixed in 2023.05.32023-08-25
CVE-2023-41249 [MEDIUM] CWE-79 CVE-2023-41249: In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
nvd
CVE-2022-36322P3HIGHCVSS 8.8fixed in 2022.04.2≥ 2022.04.2, < 2022.04.22022-07-20
CVE-2022-36322 [HIGH] CWE-88 CVE-2022-36322: In JetBrains TeamCity before 2022.04.2 build parameter injection was possible In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
nvd
CVE-2022-24342P3HIGHCVSS 8.8fixed in 2021.2.12022-02-25
CVE-2022-24342 [HIGH] CWE-352 CVE-2022-24342: In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
nvd
CVE-2026-44413P3HIGHCVSS 7.5fixed in 2025.11.5fixed in 2026.1 2025.11.52026-05-11
CVE-2026-44413 [HIGH] CWE-306 CVE-2026-44413: In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unautho In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
nvd
CVE-2025-54530P3CRITICALCVSS 9.8fixed in 2025.072025-07-28
CVE-2025-54530 [CRITICAL] CWE-276 CVE-2025-54530: In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory pe In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
nvd
CVE-2026-59796P3HIGHCVSS 8.1fixed in 2026.1.22026-07-10
CVE-2026-59796 [HIGH] CWE-862 CVE-2026-59796: In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
nvd
CVE-2024-24942P3MEDIUMCVSS 5.3fixed in 2023.11.32024-02-06
CVE-2024-24942 [MEDIUM] CWE-23 CVE-2024-24942: In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
nvd
Jetbrains Teamcity vulnerabilities | cvebase