Exposición de TeamCity

CI
58
score de exposición
1
sitios usan
4
en explotación
6
críticos
Análisis Vexday

TeamCity acumula 176 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 3,8 vezes acima da média geral do catálogo, o que indica risco operacional concreto e não apenas teórico. O pior caso ativo no momento é CVE-2024-27199, com EPSS de 0,9999, sinalizando probabilidade de exploração próxima da certeza estatística e exigindo atenção imediata de equipes de resposta. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), mas a presença de 4 CVEs críticas e 12 vulnerabilidades surgidas nos últimos 90 dias aponta para uma superfície de ataque ainda em expansão. Ambientes que executam TeamCity devem priorizar a aplicação de patches recentes e monitorar ativamente indicadores de comprometimento associados às vulnerabilidades em exploração confirmada.

CVEs

183 resultados
CVE-2024-27199HIGHIn JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possibleEPSS 100.0%KEVCVE-2023-42793CRITICALIn JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possibleEPSS 100.0%KEVCVE-2024-27198CRITICALIn JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possibleEPSS 99.9%KEVCVE-2026-63077CRITICALIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocolEPSS 1.0%KEVCVE-2024-31138MEDIUMIn JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settingsEPSS 74.5%CVE-2022-48428MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possibleEPSS 68.0%CVE-2023-34220MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possibleEPSS 61.2%CVE-2023-34225MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possibleEPSS 60.7%CVE-2022-48343MEDIUMIn JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.EPSS 59.5%CVE-2025-46618LOWIn JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tabEPSS 59.0%CVE-2024-23917CRITICALIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleEPSS 53.7%CVE-2023-41249MEDIUMIn JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build StepEPSS 53.1%CVE-2024-24942MEDIUMIn JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archivesEPSS 32.0%CVE-2025-31140MEDIUMIn JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles pageEPSS 27.2%CVE-2024-47949MEDIUMIn JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary locationEPSS 23.5%CVE-2025-52876MEDIUMIn JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possibleEPSS 17.1%CVE-2025-52877MEDIUMIn JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possibleEPSS 16.7%CVE-2026-49373HIGHIn JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settingsEPSS 13.0%CVE-2025-59456MEDIUMIn JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive uploadEPSS 12.2%CVE-2025-68165MEDIUMIn JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setupEPSS 3.7%