Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jetbrains Subscribe
Filtered by product Teamcity
Total 109 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-48342 1 Jetbrains 1 Teamcity 2023-03-03 N/A 9.8 CRITICAL
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-48343 1 Jetbrains 1 Teamcity 2023-03-03 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-48344 1 Jetbrains 1 Teamcity 2023-03-02 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-46830 1 Jetbrains 1 Teamcity 2022-12-12 N/A 5.3 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-46831 1 Jetbrains 1 Teamcity 2022-12-12 N/A 4.9 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVE-2022-44622 1 Jetbrains 1 Teamcity 2022-11-03 N/A 5.3 MEDIUM
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
CVE-2022-44623 1 Jetbrains 1 Teamcity 2022-11-03 N/A 7.5 HIGH
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
CVE-2022-44624 1 Jetbrains 1 Teamcity 2022-11-03 N/A 7.5 HIGH
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
CVE-2022-44646 1 Jetbrains 1 Teamcity 2022-11-03 N/A 5.3 MEDIUM
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
CVE-2022-40979 1 Jetbrains 1 Teamcity 2022-09-26 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
CVE-2022-38133 1 Jetbrains 1 Teamcity 2022-08-12 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
CVE-2022-36321 1 Jetbrains 1 Teamcity 2022-07-27 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
CVE-2022-36322 1 Jetbrains 1 Teamcity 2022-07-27 N/A 8.8 HIGH
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
CVE-2021-25775 1 Jetbrains 1 Teamcity 2022-07-12 5.5 MEDIUM 3.8 LOW
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
CVE-2021-43196 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
CVE-2021-37546 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
CVE-2021-25778 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
CVE-2022-29929 1 Jetbrains 1 Teamcity 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
CVE-2022-29928 1 Jetbrains 1 Teamcity 2022-05-23 4.0 MEDIUM 4.9 MEDIUM
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
CVE-2022-29927 1 Jetbrains 1 Teamcity 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible