Exposición de TeamCity

CI
52
score de exposición
1
sitios usan
4
en explotación
6
críticos
Análisis Vexday

TeamCity acumula 176 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 3,8 vezes acima da média geral do catálogo, o que indica risco operacional concreto e não apenas teórico. O pior caso ativo no momento é CVE-2024-27199, com EPSS de 0,9999, sinalizando probabilidade de exploração próxima da certeza estatística e exigindo atenção imediata de equipes de resposta. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), mas a presença de 4 CVEs críticas e 12 vulnerabilidades surgidas nos últimos 90 dias aponta para uma superfície de ataque ainda em expansão. Ambientes que executam TeamCity devem priorizar a aplicação de patches recentes e monitorar ativamente indicadores de comprometimento associados às vulnerabilidades em exploração confirmada.

CVEs

183 resultados
CVE-2024-31134MEDIUMIn JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registratioEPSS 0.4%CVE-2024-31140MEDIUMIn JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing toolsEPSS 0.4%CVE-2026-65907CRITICALIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possibleEPSS 0.4%CVE-2025-26492HIGHIn JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resourcesEPSS 0.4%CVE-2025-59455MEDIUMIn JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race conditionEPSS 0.4%CVE-2024-41827HIGHIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.4%CVE-2023-39173MEDIUMIn JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account accessEPSS 0.4%CVE-2023-34228MEDIUMIn JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actionsEPSS 0.4%CVE-2024-36378MEDIUMIn JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokensEPSS 0.4%CVE-2024-31137MEDIUMIn JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configurationEPSS 0.4%CVE-2022-48344MEDIUMIn JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.EPSS 0.4%CVE-2025-26493MEDIUMIn JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tabEPSS 0.4%CVE-2022-44646LOWIn JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settingsEPSS 0.4%CVE-2023-41250LOWIn JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registrationEPSS 0.4%CVE-2023-41248MEDIUMIn JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configurationEPSS 0.4%CVE-2024-24937MEDIUMIn JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possibleEPSS 0.4%CVE-2022-40979MEDIUMIn JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executableEPSS 0.4%CVE-2025-31141LOWIn JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles pageEPSS 0.4%CVE-2023-34219MEDIUMIn JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration seEPSS 0.4%CVE-2026-59796HIGHIn JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checksEPSS 0.4%