← Back

Teamcity

teamcity

Vendor: Jetbrains • 273 CVEs

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
May 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 8, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system admi...Show more
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 3, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 3, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
1Jetbrains
1Teamcity
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 10, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 20, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
1Jetbrains
1Teamcity
Jun 17, 2026
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 12, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
1Jetbrains
1Teamcity
Jun 17, 2026
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible