Exposure of TeamCity

CI
55
exposure score
1
sites use
4
exploited
6
critical

CVEs

188 results
CVE-2024-35301MEDIUMIn JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App tokenEPSS 0.3%CVE-2026-28195MEDIUMIn JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurationsEPSS 0.3%CVE-2025-54537MEDIUMIn JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshotsEPSS 0.3%CVE-2025-54538MEDIUMIn JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" commandEPSS 0.3%CVE-2024-36371MEDIUMIn JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possibleEPSS 0.3%CVE-2025-47854MEDIUMIn JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root pageEPSS 0.3%CVE-2025-68164LOWIn JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection testEPSS 0.2%CVE-2024-56356MEDIUMIn JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attackEPSS 0.2%CVE-2024-43808LOWIn JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault pluginEPSS 0.2%CVE-2024-29880MEDIUMIn JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent processEPSS 0.2%CVE-2026-49380LOWIn JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possibleEPSS 0.2%CVE-2025-67740LOWIn JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadataEPSS 0.2%CVE-2025-54533MEDIUMIn JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configurationEPSS 0.2%CVE-2025-54532MEDIUMIn JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependenciesEPSS 0.2%CVE-2025-68267MEDIUMIn JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installaEPSS 0.2%CVE-2025-68162LOWIn JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configurationEPSS 0.2%CVE-2025-68268MEDIUMIn JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings pageEPSS 0.2%CVE-2025-68166MEDIUMIn JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tabEPSS 0.2%CVE-2025-68163LOWIn JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall pageEPSS 0.2%CVE-2025-54530HIGHIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.2%