← Back

Teamcity

teamcity

Vendor: Jetbrains • 273 CVEs

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 2, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
1Jetbrains
2Teamcity
Upsource
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.