Exposição de TeamCity

CI
52
score de exposição
1
sites usam
4
em exploração
6
críticos
Análise Vexday

TeamCity acumula 176 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 3,8 vezes acima da média geral do catálogo, o que indica risco operacional concreto e não apenas teórico. O pior caso ativo no momento é CVE-2024-27199, com EPSS de 0,9999, sinalizando probabilidade de exploração próxima da certeza estatística e exigindo atenção imediata de equipes de resposta. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), mas a presença de 4 CVEs críticas e 12 vulnerabilidades surgidas nos últimos 90 dias aponta para uma superfície de ataque ainda em expansão. Ambientes que executam TeamCity devem priorizar a aplicação de patches recentes e monitorar ativamente indicadores de comprometimento associados às vulnerabilidades em exploração confirmada.

CVEs

183 resultados
CVE-2024-36363MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possibleEPSS 0.3%CVE-2024-36368MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possibleEPSS 0.3%CVE-2024-36369MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possibleEPSS 0.3%CVE-2024-36370MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possibleEPSS 0.3%CVE-2024-36373MEDIUMIn JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possibleEPSS 0.3%CVE-2024-36374MEDIUMIn JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possibleEPSS 0.3%CVE-2024-43810MEDIUMIn JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core pluginEPSS 0.3%CVE-2024-35301MEDIUMIn JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App tokenEPSS 0.3%CVE-2026-49371HIGHIn JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possibleEPSS 0.3%CVE-2026-49379MEDIUMIn JetBrains TeamCity before 2026.1 credentials could be exposed in thread namesEPSS 0.3%CVE-2025-54538MEDIUMIn JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" commandEPSS 0.3%CVE-2025-54537MEDIUMIn JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshotsEPSS 0.3%CVE-2024-36371MEDIUMIn JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possibleEPSS 0.3%CVE-2025-47854MEDIUMIn JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root pageEPSS 0.3%CVE-2025-68164LOWIn JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection testEPSS 0.2%CVE-2024-43808LOWIn JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault pluginEPSS 0.2%CVE-2024-56356MEDIUMIn JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attackEPSS 0.2%CVE-2026-49374HIGHIn JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parametersEPSS 0.2%CVE-2024-29880MEDIUMIn JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent processEPSS 0.2%CVE-2026-49375MEDIUMIn JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download pageEPSS 0.2%