Jetbrains Teamcity vulnerabilities
276 known vulnerabilities affecting jetbrains/teamcity.
Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9
Vulnerabilities
Page 2 of 14
CVE-2025-46433P3CRITICALCVSS 9.8fixed in 2025.03.12025-04-25
CVE-2025-46433 [CRITICAL] CWE-23 CVE-2025-46433: In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possi
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
nvd
CVE-2025-54531P3CRITICALCVSS 9.4fixed in 2025.072025-07-28
CVE-2025-54531 [CRITICAL] CWE-23 CVE-2025-54531: In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
nvd
CVE-2024-31138P3MEDIUMCVSS 5.4fixed in 2024.032024-03-28
CVE-2024-31138 [MEDIUM] CWE-79 CVE-2024-31138: In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
nvd
CVE-2019-12157P3CRITICALCVSS 9.8fixed in 2018.2.52019-10-02
CVE-2019-12157 [CRITICAL] CWE-20 CVE-2019-12157: In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC comm
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
nvd
CVE-2023-39173P3HIGHCVSS 8.8fixed in 2023.05.22023-07-25
CVE-2023-39173 [HIGH] CWE-266 CVE-2023-39173: In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full a
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
nvd
CVE-2024-56351P3HIGHCVSS 8.8fixed in 2024.122024-12-20
CVE-2024-56351 [HIGH] CWE-613 CVE-2024-56351: In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
nvd
CVE-2022-48428P3MEDIUMCVSS 5.4fixed in 2022.10.32023-03-27
CVE-2022-48428 [MEDIUM] CWE-79 CVE-2022-48428: In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
nvd
CVE-2022-48343P3MEDIUMCVSS 6.1fixed in 2022.10.22023-02-23
CVE-2022-48343 [MEDIUM] CWE-79 CVE-2022-48343: In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
nvd
CVE-2023-34225P3MEDIUMCVSS 5.4fixed in 2023.052023-05-31
CVE-2023-34225 [MEDIUM] CWE-79 CVE-2023-34225: In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
nvd
CVE-2024-41827P3CRITICALCVSS 9.8fixed in 2024.072024-07-22
CVE-2024-41827 [CRITICAL] CWE-613 CVE-2024-41827: In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirati
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
nvd
CVE-2023-34220P3MEDIUMCVSS 5.4fixed in 2023.052023-05-31
CVE-2023-34220 [MEDIUM] CWE-79 CVE-2023-34220: In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
nvd
CVE-2025-67742P3HIGHCVSS 7.5fixed in 2025.112025-12-11
CVE-2025-67742 [HIGH] CWE-22 CVE-2025-67742: In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
nvd
CVE-2023-34218P3CRITICALCVSS 9.8fixed in 2023.052023-05-31
CVE-2023-34218 [CRITICAL] CWE-863 CVE-2023-34218: In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions w
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
nvd
CVE-2023-41249P3MEDIUMCVSS 6.1fixed in 2023.05.32023-08-25
CVE-2023-41249 [MEDIUM] CWE-79 CVE-2023-41249: In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
nvd
CVE-2022-36322P3HIGHCVSS 8.8fixed in 2022.04.2≥ 2022.04.2, < 2022.04.22022-07-20
CVE-2022-36322 [HIGH] CWE-88 CVE-2022-36322: In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
nvd
CVE-2022-24342P3HIGHCVSS 8.8fixed in 2021.2.12022-02-25
CVE-2022-24342 [HIGH] CWE-352 CVE-2022-24342: In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
nvd
CVE-2026-44413P3HIGHCVSS 7.5fixed in 2025.11.5fixed in 2026.1
2025.11.52026-05-11
CVE-2026-44413 [HIGH] CWE-306 CVE-2026-44413: In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unautho
In JetBrains TeamCity before 2026.1
2025.11.5 authenticated users could expose server API to unauthorised access
nvd
CVE-2025-54530P3CRITICALCVSS 9.8fixed in 2025.072025-07-28
CVE-2025-54530 [CRITICAL] CWE-276 CVE-2025-54530: In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory pe
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
nvd
CVE-2026-59796P3HIGHCVSS 8.1fixed in 2026.1.22026-07-10
CVE-2026-59796 [HIGH] CWE-862 CVE-2026-59796: In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
nvd
CVE-2024-24942P3MEDIUMCVSS 5.3fixed in 2023.11.32024-02-06
CVE-2024-24942 [MEDIUM] CWE-23 CVE-2024-24942: In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
nvd