Low
CVSS: 3.5
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Medium
CVSS: 4.9
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
Medium
CVSS: 4.3
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
Low
CVSS: 2.7
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
Medium
CVSS: 4.6
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
Medium
CVSS: 4.3
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
Medium
CVSS: 4.6
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
High
CVSS: 7.7
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
Medium
CVSS: 6.5
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
Medium
CVSS: 4.3
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Medium
CVSS: 4.6
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page