Medium
CVSS: 5.5
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
Medium
CVSS: 5.5
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
Medium
CVSS: 5.4
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
Medium
CVSS: 5.8
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
Medium
CVSS: 4.8
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
Medium
CVSS: 4.3
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
Medium
CVSS: 4.3
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
High
CVSS: 7.7
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
High
CVSS: 7.5
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
Low
CVSS: 3.7
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
Medium
CVSS: 5.4
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
Medium
CVSS: 4.8
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
Medium
CVSS: 4.3
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
Medium
CVSS: 4.8
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
Medium
CVSS: 5.4
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
Medium
CVSS: 5.4
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
Medium
CVSS: 4.3
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
Medium
CVSS: 4.8
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
Medium
CVSS: 4.8
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
Medium
CVSS: 4.8
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible