Exposição de TeamCity

CI
58
score de exposição
1
sites usam
4
em exploração
6
críticos
Análise Vexday

TeamCity acumula 176 CVEs catalogadas, com 3 confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 3,8 vezes acima da média geral do catálogo, o que indica risco operacional concreto e não apenas teórico. O pior caso ativo no momento é CVE-2024-27199, com EPSS de 0,9999, sinalizando probabilidade de exploração próxima da certeza estatística e exigindo atenção imediata de equipes de resposta. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), mas a presença de 4 CVEs críticas e 12 vulnerabilidades surgidas nos últimos 90 dias aponta para uma superfície de ataque ainda em expansão. Ambientes que executam TeamCity devem priorizar a aplicação de patches recentes e monitorar ativamente indicadores de comprometimento associados às vulnerabilidades em exploração confirmada.

CVEs

183 resultados
CVE-2025-24459MEDIUMIn JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection pageEPSS 2.8%CVE-2025-47851MEDIUMIn JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possibleEPSS 2.3%CVE-2022-36321MEDIUMIn JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some casesEPSS 1.8%CVE-2023-39174MEDIUMIn JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackersEPSS 1.7%CVE-2022-29927MEDIUMIn JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possibleEPSS 1.5%CVE-2024-47951LOWIn JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settingsEPSS 1.5%CVE-2024-47950LOWIn JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settingsEPSS 1.5%CVE-2023-38062MEDIUMIn JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurationsEPSS 1.4%CVE-2023-34223MEDIUMIn JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some casesEPSS 1.3%CVE-2022-48426MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possibleEPSS 1.1%CVE-2023-39175MEDIUMIn JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possibleEPSS 1.0%CVE-2023-34226MEDIUMIn JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possibleEPSS 1.0%CVE-2023-34222MEDIUMIn JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possibleEPSS 1.0%CVE-2023-38066MEDIUMIn JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloadsEPSS 1.0%CVE-2023-34221MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possibleEPSS 1.0%CVE-2023-38065MEDIUMIn JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possibleEPSS 1.0%CVE-2023-38063MEDIUMIn JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possibleEPSS 1.0%CVE-2023-38061MEDIUMIn JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possibleEPSS 1.0%CVE-2023-34229MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possibleEPSS 1.0%CVE-2025-52879MEDIUMIn JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possibleEPSS 1.0%