JetBrains TeamCity Base64 Password Exposure Vulnerability

Vulnerability

A vulnerability exists in JetBrains TeamCity versions prior to 2025.03, where base64 encoded passwords could be inadvertently revealed in the build log. This issue could lead to the exposure of sensitive credentials, potentially allowing unauthorized access or actions within the TeamCity environment.

Impact

Exposing base64 encoded passwords in build logs could lead to unauthorized access or actions, depending on the context in which the credentials are used.

Remediation

Users can update to TeamCity version 2025.03.1 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.