← Back

Teamcity

teamcity

Vendor: Jetbrains • 273 CVEs

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 1, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 1, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
1Jetbrains
1Teamcity
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
1Jetbrains
1Teamcity
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
1Jetbrains
1Teamcity
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors.