Exposure of TeamCity

CI
55
exposure score
1
sites use
4
exploited
6
critical

CVEs

188 results
CVE-2023-34218CRITICALIn JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possibleEPSS 0.6%CVE-2022-44624MEDIUMIn JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special charactersEPSS 0.6%CVE-2022-44623MEDIUMIn JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settingsEPSS 0.6%CVE-2025-46433MEDIUMIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.5%CVE-2024-31136HIGHIn JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameterEPSS 0.5%CVE-2024-47948MEDIUMIn JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backupsEPSS 0.5%CVE-2024-28173MEDIUMIn JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosedEPSS 0.5%CVE-2023-34227MEDIUMIn JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacksEPSS 0.5%CVE-2024-36362MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was posEPSS 0.5%CVE-2023-38067MEDIUMIn JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-38064MEDIUMIn JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2025-67741MEDIUMIn JetBrains TeamCity before 2025.11 stored XSS was possible via session attributeEPSS 0.5%CVE-2022-29928MEDIUMIn JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possibleEPSS 0.5%CVE-2026-59793HIGHIn JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integrationEPSS 0.5%CVE-2024-31139MEDIUMIn JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detectorEPSS 0.5%CVE-2024-31135MEDIUMIn JetBrains TeamCity before 2024.03 open redirect was possible on the login pageEPSS 0.5%CVE-2022-46830MEDIUMIn JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.EPSS 0.5%CVE-2022-29929LOWIn JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possibleEPSS 0.5%CVE-2026-100254HIGHIn JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection EPSS 0.5%CVE-2022-44622LOWIn JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessiveEPSS 0.5%