Exposição de TeamCity

CI
52
score de exposição
1
sites usam
4
em exploração
6
críticos
Análise Vexday

TeamCity acumula 176 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 3,8 vezes acima da média geral do catálogo, o que indica risco operacional concreto e não apenas teórico. O pior caso ativo no momento é CVE-2024-27199, com EPSS de 0,9999, sinalizando probabilidade de exploração próxima da certeza estatística e exigindo atenção imediata de equipes de resposta. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), mas a presença de 4 CVEs críticas e 12 vulnerabilidades surgidas nos últimos 90 dias aponta para uma superfície de ataque ainda em expansão. Ambientes que executam TeamCity devem priorizar a aplicação de patches recentes e monitorar ativamente indicadores de comprometimento associados às vulnerabilidades em exploração confirmada.

CVEs

183 resultados
CVE-2026-49372HIGHIn JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possibleEPSS 0.3%CVE-2024-41824MEDIUMIn JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific casesEPSS 0.3%CVE-2024-41826LOWIn JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection pageEPSS 0.3%CVE-2024-35300LOWIn JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possibleEPSS 0.3%CVE-2024-39879MEDIUMIn JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settingsEPSS 0.3%CVE-2025-54531HIGHIn JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on WindowsEPSS 0.3%CVE-2024-41828LOWIn JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant timeEPSS 0.3%CVE-2024-36365MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agentEPSS 0.3%CVE-2024-36366MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering oEPSS 0.3%CVE-2024-56348MEDIUMIn JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agentsEPSS 0.3%CVE-2024-56350MEDIUMIn JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projectsEPSS 0.3%CVE-2025-57733MEDIUMIn JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email contentEPSS 0.3%CVE-2024-39878MEDIUMIn JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App ConnectionEPSS 0.3%CVE-2024-56349MEDIUMIn JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logsEPSS 0.3%CVE-2024-35302MEDIUMIn JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possibleEPSS 0.3%CVE-2025-24460MEDIUMIn JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent poolEPSS 0.3%CVE-2024-36372MEDIUMIn JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possibleEPSS 0.3%CVE-2024-36367MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possibleEPSS 0.3%CVE-2026-44413HIGHIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised accessEPSS 0.3%CVE-2024-41825MEDIUMIn JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tabEPSS 0.3%