📦 Teamcity

by Jetbrains

🔍 What is Teamcity?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-27198

CRITICAL CVSS 9.8 Mar 4, 2024

CVE-2024-27198 is an authentication bypass vulnerability in JetBrains TeamCity CI/CD servers that allows unauthenticated attackers to perform administrative actions. This affects all TeamCity servers ...

CVE-2024-23917

CRITICAL CVSS 9.8 Feb 6, 2024

This critical vulnerability in JetBrains TeamCity allows attackers to bypass authentication mechanisms and achieve remote code execution (RCE) on affected servers. Organizations using TeamCity version...

CVE-2023-42793

CRITICAL CVSS 9.8 Sep 19, 2023

CVE-2023-42793 is a critical authentication bypass vulnerability in JetBrains TeamCity CI/CD servers that allows unauthenticated attackers to execute arbitrary code remotely. This affects all organiza...

CVE-2023-34218

CRITICAL CVSS 9.1 May 31, 2023

This vulnerability in JetBrains TeamCity allows attackers to bypass permission checks and perform administrative actions without proper authorization. It affects all TeamCity installations running ver...

CVE-2022-24340

CRITICAL CVSS 9.8 Feb 25, 2022

This vulnerability allows XML External Entity (XXE) attacks during configuration file parsing in JetBrains TeamCity. Attackers can read arbitrary files from the server, potentially leading to sensitiv...

CVE-2022-24331

CRITICAL CVSS 9.8 Feb 25, 2022

This vulnerability in JetBrains TeamCity allows attackers to impersonate users through GitLab authentication flaws. It affects TeamCity instances using GitLab authentication before version 2021.1.4. A...

CVE-2021-43202

CRITICAL CVSS 9.8 Nov 30, 2021

This vulnerability allows clickjacking attacks by missing X-Frame-Options headers in JetBrains TeamCity instances. Attackers can embed vulnerable pages in iframes to trick users into performing uninte...

CVE-2021-43193

CRITICAL CVSS 9.8 Nov 9, 2021

This vulnerability allows remote attackers to execute arbitrary code on JetBrains TeamCity servers by exploiting the agent push functionality. It affects all TeamCity installations before version 2021...

CVE-2021-43200

CRITICAL CVSS 9.8 Nov 9, 2021

This vulnerability in JetBrains TeamCity allows attackers to bypass permission checks in the Agent Push functionality, potentially enabling unauthorized code execution or system compromise. It affects...

CVE-2021-37544

CRITICAL CVSS 9.8 Aug 6, 2021

CVE-2021-37544 is an insecure deserialization vulnerability in JetBrains TeamCity that allows remote attackers to execute arbitrary code on affected servers. This affects TeamCity installations before...

CVE-2021-31914

CRITICAL CVSS 9.8 May 11, 2021

This vulnerability allows attackers to execute arbitrary code on JetBrains TeamCity servers running on Windows. It affects TeamCity installations before version 2020.2.4 on Windows operating systems, ...

CVE-2021-31909

CRITICAL CVSS 9.8 May 11, 2021

This vulnerability allows remote attackers to execute arbitrary code on JetBrains TeamCity servers by injecting malicious arguments. It affects all TeamCity installations before version 2020.2.3. Atta...

CVE-2025-59457

HIGH CVSS 7.7 Sep 17, 2025

This vulnerability in JetBrains TeamCity allows attackers to leak credentials on Windows systems due to insufficient Git URL validation. It affects TeamCity installations on Windows where Git reposito...

CVE-2025-54530

HIGH CVSS 7.5 Jul 28, 2025

This vulnerability in JetBrains TeamCity allows attackers to escalate privileges due to incorrect directory permissions. It affects all TeamCity installations before version 2025.07. Attackers could g...

CVE-2025-26492

HIGH CVSS 7.7 Feb 11, 2025

This vulnerability in JetBrains TeamCity allows attackers to access sensitive Kubernetes resources due to improper connection settings. Organizations using TeamCity with Kubernetes integration are aff...

CVE-2024-43114

HIGH CVSS 7.5 Aug 6, 2024

This vulnerability in JetBrains TeamCity allows attackers to escalate privileges due to incorrect directory permissions. It affects all TeamCity installations before version 2024.07.1. Attackers could...

CVE-2024-41827

HIGH CVSS 7.4 Jul 22, 2024

This vulnerability allows access tokens in JetBrains TeamCity to remain functional after they have been deleted or expired, creating an authentication bypass. Any TeamCity server with access tokens co...

CVE-2024-36470

HIGH CVSS 8.1 May 29, 2024

This CVE describes an authentication bypass vulnerability in JetBrains TeamCity CI/CD servers. Attackers could potentially gain unauthorized access to TeamCity instances in specific edge cases. Organi...

CVE-2024-31136

HIGH CVSS 7.4 Mar 28, 2024

This vulnerability allows attackers to bypass two-factor authentication (2FA) in JetBrains TeamCity by using a special URL parameter. It affects all TeamCity instances with 2FA enabled that are runnin...

CVE-2022-25264

HIGH CVSS 7.5 Feb 25, 2022

This vulnerability in JetBrains TeamCity allows environment variables marked as 'password' type to be logged in certain cases, potentially exposing sensitive credentials. It affects TeamCity installat...

CVE-2022-24335

HIGH CVSS 8.1 Feb 25, 2022

This vulnerability in JetBrains TeamCity allows attackers to exploit a race condition during agent registration via XML-RPC, potentially enabling unauthorized agent registration or privilege escalatio...

CVE-2022-24342

HIGH CVSS 8.8 Feb 25, 2022

This vulnerability in JetBrains TeamCity allows attackers to inject malicious URLs that can lead to Cross-Site Request Forgery (CSRF) attacks. It affects TeamCity servers running versions before 2021....

CVE-2021-43196

HIGH CVSS 7.5 Nov 9, 2021

This vulnerability in JetBrains TeamCity allows attackers to access sensitive information through the Docker Registry connection dialog. It affects TeamCity instances before version 2021.1. The inform...

CVE-2021-37548

HIGH CVSS 7.5 Aug 6, 2021

JetBrains TeamCity versions before 2021.1 could store passwords in cleartext within version control systems (VCS). This vulnerability allows attackers with access to VCS repositories to obtain sensiti...

CVE-2021-31910

HIGH CVSS 7.5 May 11, 2021

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in JetBrains TeamCity that allows attackers to make unauthorized requests from the server to internal systems. It affects TeamCity...

CVE-2021-31912

HIGH CVSS 8.8 May 11, 2021

CVE-2021-31912 is an account takeover vulnerability in JetBrains TeamCity where attackers could potentially hijack user accounts during password reset processes. This affects organizations running Tea...

CVE-2021-26310

HIGH CVSS 7.5 May 11, 2021

This vulnerability in the TeamCity IntelliJ plugin allows denial-of-service attacks by crashing the plugin or IDE. It affects developers using IntelliJ IDEA with the TeamCity plugin installed. The vul...

CVE-2026-28195

MEDIUM CVSS 4.3 Feb 25, 2026

This CVE describes a missing authorization vulnerability in JetBrains TeamCity where project developers can add parameters to build configurations without proper permission checks. This affects TeamCi...

CVE-2025-68165

MEDIUM CVSS 5.4 Dec 16, 2025

JetBrains TeamCity versions before 2025.11 contain a reflected cross-site scripting (XSS) vulnerability in the VCS Root setup interface. This allows attackers to inject malicious scripts that execute ...

CVE-2025-68166

MEDIUM CVSS 5.4 Dec 16, 2025

This DOM-based cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into the OAuth connections tab. When exploited, it could enable session hijac...

CVE-2025-68267

MEDIUM CVSS 6.5 Dec 16, 2025

JetBrains TeamCity versions before 2025.11.1 stored GitHub personal access tokens instead of installation tokens, granting excessive privileges. This vulnerability allows attackers with access to thes...

CVE-2025-68268

MEDIUM CVSS 5.4 Dec 16, 2025

This vulnerability allows attackers to inject malicious scripts into the JetBrains TeamCity storage settings page, which are then executed in victims' browsers when they view the page. It affects all ...

CVE-2025-67741

MEDIUM CVSS 4.6 Dec 11, 2025

This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into session attributes that persist and execute when other users view affected ...

CVE-2025-59455

MEDIUM CVSS 4.2 Sep 17, 2025

This CVE describes a project isolation bypass vulnerability in JetBrains TeamCity due to a race condition. Attackers could potentially access or modify project data they shouldn't have permission to v...

CVE-2025-59456

MEDIUM CVSS 5.5 Sep 17, 2025

This vulnerability allows attackers to perform path traversal attacks during project archive uploads in JetBrains TeamCity, potentially enabling unauthorized file access or manipulation. Organizations...

CVE-2025-57733

MEDIUM CVSS 5.5 Aug 20, 2025

This CVE describes an SMTP injection vulnerability in JetBrains TeamCity that allows attackers to modify email content sent by the application. Attackers could potentially alter email headers, body co...

CVE-2025-57734

MEDIUM CVSS 4.3 Aug 20, 2025

This vulnerability exposes AWS credentials in Docker script files within JetBrains TeamCity CI/CD servers. Attackers who gain access to these files could potentially use the credentials to access AWS ...

CVE-2025-54538

MEDIUM CVSS 5.5 Jul 28, 2025

This vulnerability in JetBrains TeamCity allows passwords to be exposed via command line arguments when using the 'hg pull' command. Attackers with access to process listings could potentially capture...

CVE-2025-54534

MEDIUM CVSS 4.8 Jul 28, 2025

This vulnerability allows reflected cross-site scripting (XSS) attacks on JetBrains TeamCity's agentpushPreset page. Attackers can inject malicious scripts that execute in users' browsers when they vi...

CVE-2025-54536

MEDIUM CVSS 5.4 Jul 28, 2025

This Cross-Site Request Forgery (CSRF) vulnerability in JetBrains TeamCity allows attackers to trick authenticated users into performing unintended GraphQL operations. Attackers could modify data or p...

CVE-2025-54532

MEDIUM CVSS 4.3 Jul 28, 2025

This vulnerability in JetBrains TeamCity allows unauthorized users to access sensitive build configuration settings through snapshot dependencies. It affects organizations using TeamCity for CI/CD pip...

CVE-2025-54528

MEDIUM CVSS 5.4 Jul 28, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in JetBrains TeamCity's GitHub App connection flow allows attackers to trick authenticated users into performing unauthorized actions. This affects Te...

CVE-2025-52876

MEDIUM CVSS 5.4 Jun 23, 2025

This vulnerability allows reflected cross-site scripting (XSS) attacks on the favoriteIcon page in JetBrains TeamCity. Attackers can inject malicious scripts that execute in users' browsers when they ...

CVE-2025-52878

MEDIUM CVSS 4.3 Jun 23, 2025

This vulnerability in JetBrains TeamCity exposes usernames to users who lack proper permissions to view them. It affects organizations using TeamCity for CI/CD pipelines where user enumeration could r...

CVE-2025-47851

MEDIUM CVSS 4.8 May 20, 2025

This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts via GitHub Checks Webhooks. When exploited, these scripts execute in the context...

CVE-2025-47853

MEDIUM CVSS 4.8 May 20, 2025

This vulnerability allows attackers to inject malicious scripts into JetBrains TeamCity's Jira integration interface, which are then stored and executed when other users view the affected pages. It af...

CVE-2025-46433

MEDIUM CVSS 4.9 Apr 25, 2025

This vulnerability in JetBrains TeamCity allows attackers to bypass path validation in the loggingPreset parameter, potentially enabling unauthorized file access or manipulation. It affects all TeamCi...

CVE-2025-31140

MEDIUM CVSS 4.6 Mar 27, 2025

This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into the Cloud Profiles page. When other users view the compromised page, the sc...

CVE-2025-26493

MEDIUM CVSS 4.6 Feb 11, 2025

Multiple DOM-based cross-site scripting (XSS) vulnerabilities exist in JetBrains TeamCity's Code Inspection Report tab. These allow attackers to inject malicious scripts that execute in users' browser...

CVE-2025-24461

MEDIUM CVSS 6.5 Jan 21, 2025

This vulnerability in JetBrains TeamCity allows unauthorized decryption of connection secrets via the Test Connection endpoint. Attackers with access to the endpoint can potentially retrieve sensitive...

CVE-2025-24459

MEDIUM CVSS 4.6 Jan 21, 2025

This vulnerability allows reflected cross-site scripting (XSS) attacks on the Vault Connection page in JetBrains TeamCity. Attackers can inject malicious scripts that execute in users' browsers when t...

CVE-2024-56353

MEDIUM CVSS 5.5 Dec 20, 2024

JetBrains TeamCity backup files exposed user credentials and session cookies in versions before 2024.12. This vulnerability allows attackers with access to backup files to steal authentication data. O...

CVE-2024-56355

MEDIUM CVSS 4.6 Dec 20, 2024

JetBrains TeamCity versions before 2024.12 have a cross-site scripting (XSS) vulnerability in the RemoteBuildLogController due to missing Content-Type headers in responses. This allows attackers to in...

CVE-2024-56349

MEDIUM CVSS 5.3 Dec 20, 2024

This vulnerability in JetBrains TeamCity allows unauthorized users to modify build logs due to improper access control. It affects organizations using TeamCity for CI/CD pipelines where unauthorized u...

CVE-2024-56351

MEDIUM CVSS 6.3 Dec 20, 2024

This vulnerability in JetBrains TeamCity allows access tokens to remain valid after user roles are removed, potentially enabling unauthorized access. It affects TeamCity instances before version 2024....

CVE-2024-47161

MEDIUM CVSS 4.3 Oct 8, 2024

This vulnerability in JetBrains TeamCity allows passwords to be exposed through the Sonar runner REST API. Attackers could potentially retrieve sensitive credentials from improperly configured systems...

CVE-2024-47949

MEDIUM CVSS 4.9 Oct 8, 2024

This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to write backup files to arbitrary locations on the server. Attackers could potentially overwrite critical...

CVE-2025-68164

LOW CVSS 2.7 Dec 16, 2025

This vulnerability in JetBrains TeamCity allows attackers to enumerate open ports on the server when testing Perforce connections. It affects organizations using TeamCity with Perforce integration. Th...

CVE-2025-68162

LOW CVSS 2.7 Dec 16, 2025

This vulnerability in JetBrains TeamCity allows attackers to load malicious extensions via Maven embedder through project configuration. It affects TeamCity instances with Maven build configurations. ...

CVE-2025-68163

LOW CVSS 3.5 Dec 16, 2025

This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into the agentpushInstall page, which are then executed when users view that pag...

CVE-2025-67739

LOW CVSS 3.1 Dec 11, 2025

This vulnerability in JetBrains TeamCity allows attackers to disclose local file paths through improper repository URL validation. It affects TeamCity servers with repository integrations configured. ...

CVE-2025-67740

LOW CVSS 2.7 Dec 11, 2025

This vulnerability in JetBrains TeamCity allows improper access control that could expose GitHub App token metadata. It affects organizations using TeamCity CI/CD servers with GitHub App integrations....